Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45502
Total
3651
Critical
13471
High
13397
Medium
CVE ID Severity Score Description Published
CVE-2026-15585 HIGH 7.5 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. AKINSOFT Wolvox9 ERP … Aug 18, 2026
CVE-2026-75773 LOW 3.7 A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the function authorize of the file apps/web/server/auth.ts of the component Login … Aug 18, 2026
CVE-2026-75627 CRITICAL 9.8 Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path … Aug 18, 2026
CVE-2026-75626 CRITICAL 9.3 SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event … Aug 18, 2026
CVE-2026-19608 MEDIUM 5.3 A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained access control to resources. The issue … Aug 18, 2026
CVE-2026-19447 MEDIUM 5.4 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informatics Services Trade Inc. FileOrbis allows Stored XSS. This issue affects FileOrbis: … Aug 18, 2026
CVE-2024-14046 MEDIUM 6.3 A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy of the component Document … Aug 18, 2026
CVE-2026-18929 UNKNOWN Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processing .docx files. The library uses yazl for zip … Aug 18, 2026
CVE-2026-43971 UNKNOWN Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via unescaped special characters in cow_link:link/1. cow_link:do_link/1 in cowlib interpolates … Aug 18, 2026
CVE-2024-14045 MEDIUM 6.3 A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Product Supplier Edit … Aug 18, 2026
CVE-2026-34884 UNKNOWN SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade … Aug 18, 2026
CVE-2026-15371 HIGH 8.1 Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can … Aug 18, 2026
CVE-2026-75091 HIGH 7.2 The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, … Aug 18, 2026
CVE-2026-15748 CRITICAL 9.8 The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This … Aug 18, 2026
CVE-2026-75151 MEDIUM 4.3 A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads … Aug 18, 2026
CVE-2026-11801 HIGH 7.5 The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to … Aug 18, 2026
CVE-2026-75094 CRITICAL 9.1 A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component CGI Interface. This manipulation … Aug 18, 2026
CVE-2026-75093 MEDIUM 4.3 A security vulnerability has been detected in sonos tract up to 0.23.4. This impacts the function Tensor::from_raw_dt_align of the file data/src/tensor.rs of the component ONNX … Aug 18, 2026
CVE-2026-75090 MEDIUM 4.3 A vulnerability was detected in EricLBuehler Mistral.rs up to 0.8.22. Affected by this issue is the function convert_gguf_to_hf_tokenizer of the file mistralrs-core/src/gguf/gguf_tokenizer.rs of the component … Aug 18, 2026
CVE-2026-75089 HIGH 7.3 A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file user/check_availability.php. This manipulation … Aug 18, 2026
CVE-2026-75088 MEDIUM 6.3 A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewbilling.php. Executing a manipulation of the argument … Aug 18, 2026
CVE-2026-75087 MEDIUM 6.3 A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /viewdepartment.php. Performing a manipulation of the argument … Aug 18, 2026
CVE-2026-75086 MEDIUM 6.3 A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewroom.php. Such manipulation of … Aug 18, 2026
CVE-2026-75082 MEDIUM 4.3 A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component … Aug 18, 2026
CVE-2026-75081 MEDIUM 4.3 A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id … Aug 18, 2026