Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45502
Total
3651
Critical
13471
High
13397
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-15585 | HIGH | 7.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. AKINSOFT Wolvox9 ERP … | Aug 18, 2026 |
| CVE-2026-75773 | LOW | 3.7 | A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the function authorize of the file apps/web/server/auth.ts of the component Login … | Aug 18, 2026 |
| CVE-2026-75627 | CRITICAL | 9.8 | Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path … | Aug 18, 2026 |
| CVE-2026-75626 | CRITICAL | 9.3 | SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event … | Aug 18, 2026 |
| CVE-2026-19608 | MEDIUM | 5.3 | A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained access control to resources. The issue … | Aug 18, 2026 |
| CVE-2026-19447 | MEDIUM | 5.4 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informatics Services Trade Inc. FileOrbis allows Stored XSS. This issue affects FileOrbis: … | Aug 18, 2026 |
| CVE-2024-14046 | MEDIUM | 6.3 | A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy of the component Document … | Aug 18, 2026 |
| CVE-2026-18929 | UNKNOWN | — | Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processing .docx files. The library uses yazl for zip … | Aug 18, 2026 |
| CVE-2026-43971 | UNKNOWN | — | Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via unescaped special characters in cow_link:link/1. cow_link:do_link/1 in cowlib interpolates … | Aug 18, 2026 |
| CVE-2024-14045 | MEDIUM | 6.3 | A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Product Supplier Edit … | Aug 18, 2026 |
| CVE-2026-34884 | UNKNOWN | — | SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade … | Aug 18, 2026 |
| CVE-2026-15371 | HIGH | 8.1 | Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can … | Aug 18, 2026 |
| CVE-2026-75091 | HIGH | 7.2 | The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, … | Aug 18, 2026 |
| CVE-2026-15748 | CRITICAL | 9.8 | The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This … | Aug 18, 2026 |
| CVE-2026-75151 | MEDIUM | 4.3 | A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads … | Aug 18, 2026 |
| CVE-2026-11801 | HIGH | 7.5 | The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to … | Aug 18, 2026 |
| CVE-2026-75094 | CRITICAL | 9.1 | A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid of the component CGI Interface. This manipulation … | Aug 18, 2026 |
| CVE-2026-75093 | MEDIUM | 4.3 | A security vulnerability has been detected in sonos tract up to 0.23.4. This impacts the function Tensor::from_raw_dt_align of the file data/src/tensor.rs of the component ONNX … | Aug 18, 2026 |
| CVE-2026-75090 | MEDIUM | 4.3 | A vulnerability was detected in EricLBuehler Mistral.rs up to 0.8.22. Affected by this issue is the function convert_gguf_to_hf_tokenizer of the file mistralrs-core/src/gguf/gguf_tokenizer.rs of the component … | Aug 18, 2026 |
| CVE-2026-75089 | HIGH | 7.3 | A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file user/check_availability.php. This manipulation … | Aug 18, 2026 |
| CVE-2026-75088 | MEDIUM | 6.3 | A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewbilling.php. Executing a manipulation of the argument … | Aug 18, 2026 |
| CVE-2026-75087 | MEDIUM | 6.3 | A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /viewdepartment.php. Performing a manipulation of the argument … | Aug 18, 2026 |
| CVE-2026-75086 | MEDIUM | 6.3 | A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewroom.php. Such manipulation of … | Aug 18, 2026 |
| CVE-2026-75082 | MEDIUM | 4.3 | A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component … | Aug 18, 2026 |
| CVE-2026-75081 | MEDIUM | 4.3 | A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id … | Aug 18, 2026 |