Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45656
Total
3653
Critical
13500
High
13451
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-18855 | CRITICAL | 9.1 | The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions … | Aug 15, 2026 |
| CVE-2026-19904 | LOW | 2.4 | A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file /admin/index.php?page=site_settings of the component System Settings … | Aug 15, 2026 |
| CVE-2026-19903 | MEDIUM | 5.3 | A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the component SQL Database … | Aug 15, 2026 |
| CVE-2026-19901 | HIGH | 8.1 | A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. … | Aug 15, 2026 |
| CVE-2026-19598 | CRITICAL | 9.8 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and … | Aug 15, 2026 |
| CVE-2026-19900 | HIGH | 8.1 | A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. … | Aug 15, 2026 |
| CVE-2026-19899 | HIGH | 7.3 | A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /edit_teacher.php. Executing a … | Aug 15, 2026 |
| CVE-2026-19898 | LOW | 3.7 | A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmauth/main.go of the component VMAuth Authentication Endpoint. Performing … | Aug 15, 2026 |
| CVE-2026-19897 | LOW | 3.7 | A vulnerability has been found in mangroup dtale up to 3.22.0. This issue affects the function Login of the file dtale/auth.py of the component Login … | Aug 15, 2026 |
| CVE-2026-19896 | LOW | 3.7 | A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_secret_key of the file dtale/app.py of the component Flask … | Aug 15, 2026 |
| CVE-2026-19895 | LOW | 3.7 | A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the … | Aug 15, 2026 |
| CVE-2026-19474 | HIGH | 7.5 | @fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed temporary files on … | Aug 15, 2026 |
| CVE-2026-18549 | HIGH | 7.5 | @fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a … | Aug 15, 2026 |
| CVE-2026-18500 | HIGH | 8.1 | @fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verification key passed to request.jwtVerify({ key }) is silently overridden … | Aug 15, 2026 |
| CVE-2026-18165 | MEDIUM | 4.2 | @fastify/oauth2 is an OAuth 2.0 plugin for Fastify. In versions from 7.2.0 up to but not including 8.3.0, the plugin validates the OAuth state, and … | Aug 15, 2026 |
| CVE-2026-15689 | UNKNOWN | — | Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_password_reset and _default_welcome_send. Both default emails emit a … | Aug 15, 2026 |
| CVE-2026-74577 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: mpls: initialize rtm_tos in mpls_getroute() mpls_getroute() builds the RTM_NEWROUTE reply to an RTM_GETROUTE request … | Aug 15, 2026 |
| CVE-2026-74576 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mm/slab: prevent unbounded recursion in free path with new kmalloc type Commit 280ea9c3154b ("mm/slab: avoid … | Aug 15, 2026 |
| CVE-2026-74575 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Prevent XDomain delayed work use-after-free on disconnect tb_xdp_handle_request() runs on system_wq and queues xd->state_work … | Aug 15, 2026 |
| CVE-2026-74574 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() The failed_dev_add and failed_dev_name paths drop … | Aug 15, 2026 |
| CVE-2026-74573 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE arm_vsmmu_vsid_to_sid() maps a guest's vSID to … | Aug 15, 2026 |
| CVE-2026-74572 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix deadlock between metadata writeback and transaction commit When writing out metadata extent … | Aug 15, 2026 |
| CVE-2026-74571 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: btrfs: skip global block reserve accounting for rescue mounts [BUG] Mounting with rescue=ibadroots after corrupting … | Aug 15, 2026 |
| CVE-2026-74570 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ntfs: harden runlist realloc size calculations Add a shared helper to safely convert runlist element … | Aug 15, 2026 |
| CVE-2026-74569 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() sip_help_tcp() stores the size change … | Aug 15, 2026 |