Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45502
Total
3651
Critical
13471
High
13397
Medium
CVE ID Severity Score Description Published
CVE-2026-57485 HIGH 8.5 Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /api/v1/pipeline/handleData endpoint in app/core/src/main/java/stirling/software/SPDF/controller/api/pipeline/PipelineProcessor.java injects the STIRLING-PDF-BACKEND-API-USER … Aug 17, 2026
CVE-2026-57233 HIGH 8.1 Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress function joins untrusted ZIP entry names to unzipDestTo without canonical … Aug 17, 2026
CVE-2026-54758 HIGH 7.8 Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the expandNppEnvironmentStrs function in PowerEditor/src/WinControls/StaticDialog/RunDlg/RunDlg.cpp copies a Notepad++ variable name between $( and … Aug 17, 2026
CVE-2026-52886 UNKNOWN Notepad++ is a free and open-source source code editor. Prior to 8.9.7, Notepad++ validates the backupFilePath attribute from session.xml with std::wstring::starts_with against the expected backup … Aug 17, 2026
CVE-2026-19650 HIGH 7.1 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 … Aug 17, 2026
CVE-2026-19478 CRITICAL 9.4 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 … Aug 17, 2026
CVE-2026-75011 MEDIUM 6.3 A flaw has been found in kylecui NetForensicMCP 2.1.0. Impacted is the function execAsync of the file index.js. Executing a manipulation of the argument interface/protocol … Aug 17, 2026
CVE-2026-74238 HIGH 7.5 TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote attackers to cause the decoder to read … Aug 17, 2026
CVE-2026-71693 UNKNOWN Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not … Aug 17, 2026
CVE-2026-66792 CRITICAL 9.9 A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription … Aug 17, 2026
CVE-2026-60107 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 17, 2026
CVE-2026-60106 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 17, 2026
CVE-2026-50776 UNKNOWN Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote attacker to obtain sensitive information and execute arbitrary code. Aug 17, 2026
CVE-2026-50775 UNKNOWN A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, … Aug 17, 2026
CVE-2026-50774 UNKNOWN An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role. Aug 17, 2026
CVE-2026-50773 UNKNOWN An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 allows a remote attacker to execute arbtirary code via a crafted .dll file. Aug 17, 2026
CVE-2026-45698 HIGH 7.5 Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in … Aug 17, 2026
CVE-2026-17639 UNKNOWN Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condition that allows an unauthenticated attacker to cause the device … Aug 17, 2026
CVE-2026-12553 UNKNOWN HP has identified a potential vulnerability in HP Web Jetadmin (WJA) that may allow an unauthenticated actor to read from or write to arbitrary files … Aug 17, 2026
CVE-2026-74254 UNKNOWN Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL … Aug 17, 2026
CVE-2026-74253 UNKNOWN Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 - Regular Labs Sourcerer before 14.0.0 processes {source} blocks … Aug 17, 2026
CVE-2026-73523 HIGH 7.5 COVESA Open1722 through 0.9.2 contains an integer truncation vulnerability in acf-can-listener.c that allows unauthenticated remote attackers to cause the CAN listener to transmit process stack … Aug 17, 2026
CVE-2026-73522 HIGH 7.5 COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to write past the end of a fixed 15-slot stack … Aug 17, 2026
CVE-2026-73424 MEDIUM 6.5 Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/integrations/vercel/src/serverless/entrypoint.ts accepts x_astro_path for the public /_isr function … Aug 17, 2026
CVE-2026-71980 HIGH 7.5 Belledonne Communications bcg729 through 1.1.2 contains an out-of-bounds read vulnerability in the decodeSIDframe() function in src/cng.c that allows unauthenticated network-adjacent attackers to trigger a heap … Aug 17, 2026