Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45656
Total
3653
Critical
13500
High
13451
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-49306 | LOW | 3.3 | UAF vulnerability in the time and time zone module. Impact: Successful exploitation of this vulnerability may affect availability. | Aug 17, 2026 |
| CVE-2026-49305 | MEDIUM | 6.2 | Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of this vulnerability may affect availability. | Aug 17, 2026 |
| CVE-2026-49304 | MEDIUM | 6.2 | Permission control vulnerability in the device key management module. Impact: Successful exploitation of this vulnerability may affect availability. | Aug 17, 2026 |
| CVE-2026-49303 | MEDIUM | 5.1 | Permission control vulnerability in the notification module. Impact: Successful exploitation of this vulnerability may affect availability. | Aug 17, 2026 |
| CVE-2026-49302 | MEDIUM | 6.2 | Permission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Aug 17, 2026 |
| CVE-2026-49301 | MEDIUM | 6.2 | Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Aug 17, 2026 |
| CVE-2026-20000 | MEDIUM | 6.3 | A vulnerability was detected in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewprescriptionrecord.php. The manipulation of the … | Aug 17, 2026 |
| CVE-2026-19999 | MEDIUM | 6.3 | A security vulnerability has been detected in Open Asset Import Library Assimp Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ParseBoneTrafoKeys_3DGS_MDL7 of the file code/AssetLib/MDL/MDLLoader.cpp … | Aug 17, 2026 |
| CVE-2026-19998 | MEDIUM | 4.3 | A weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown function of the file offersmail.php. Executing a manipulation of the … | Aug 17, 2026 |
| CVE-2026-22072 | UNKNOWN | — | Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens. | Aug 17, 2026 |
| CVE-2026-19997 | MEDIUM | 4.7 | A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /admin/sales/rma/requests of the component … | Aug 17, 2026 |
| CVE-2026-19996 | MEDIUM | 4.3 | A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior … | Aug 17, 2026 |
| CVE-2026-19995 | LOW | 3.5 | A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message Handler. … | Aug 17, 2026 |
| CVE-2026-19994 | MEDIUM | 6.3 | A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-management/execute of the component … | Aug 17, 2026 |
| CVE-2026-15623 | UNKNOWN | — | A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform … | Aug 17, 2026 |
| CVE-2026-74579 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: fix mask build for partial field offload nft_payload_offload_mask() builds the offload match mask … | Aug 17, 2026 |
| CVE-2026-19993 | MEDIUM | 4.3 | A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the … | Aug 17, 2026 |
| CVE-2026-19992 | LOW | 3.1 | A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown … | Aug 17, 2026 |
| CVE-2026-19988 | MEDIUM | 4.3 | A vulnerability was detected in Alaev SEO Tools Extension up to 1.0.10 on Chrome. This impacts the function addDiv of the file src/popup.html of the … | Aug 17, 2026 |
| CVE-2026-19987 | MEDIUM | 5.3 | A security vulnerability has been detected in SourceCodester Best Employee Management System 1.0. This affects an unknown function of the file /assets/uploadImage/Profile/. Such manipulation leads … | Aug 17, 2026 |
| CVE-2026-14832 | MEDIUM | 5.3 | The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or ownership check on a phone-number lookup exposed to unauthenticated users, … | Aug 17, 2026 |
| CVE-2026-13700 | MEDIUM | 5.9 | The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and attaches stored third-party integration credentials … | Aug 17, 2026 |
| CVE-2026-19986 | MEDIUM | 5.4 | A weakness has been identified in Adblock for Youtube Extension up to 7.2.1 on Chrome. The impacted element is the function updateDynamicRules of the file … | Aug 17, 2026 |
| CVE-2026-19984 | MEDIUM | 6.3 | A flaw has been found in jkawamoto mcp-florence2 up to 0.3.13. Affected by this issue is the function get_images of the file src/mcp_florence2/__init__.py. This manipulation … | Aug 17, 2026 |
| CVE-2026-19983 | HIGH | 8.3 | A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This issue affects some unknown processing of the file … | Aug 17, 2026 |