Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
46113
Total
3679
Critical
13638
High
13568
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-65974 | CRITICAL | 9.9 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in … | Aug 17, 2026 |
| CVE-2026-65832 | HIGH | 8.2 | Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthenticated Deskflow server can send kMsgDSetOptions (DSOP) values to ServerProxy::setOptions() … | Aug 17, 2026 |
| CVE-2026-65822 | HIGH | 7.6 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/report/inactive_customers/inactive_customers.py accepts an unvalidated doctype filter and interpolates it … | Aug 17, 2026 |
| CVE-2026-65640 | HIGH | 8.8 | WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and … | Aug 17, 2026 |
| CVE-2026-64657 | HIGH | 8.4 | Budibase is an open-source low-code platform. Prior to 3.39.19, the PostgreSQL datasource connector in packages/server/src/integrations/postgres.ts interpolates the user-controlled schema configuration field into a SET search_path … | Aug 17, 2026 |
| CVE-2026-63409 | HIGH | 8.2 | Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malicious Deskflow server can send an odd-length DSOP vector to … | Aug 17, 2026 |
| CVE-2026-54356 | HIGH | 7.1 | Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts and packages/server/src/api/controllers/static/index.ts allows an authenticated published-app user with the BASIC role to … | Aug 17, 2026 |
| CVE-2026-54336 | MEDIUM | 5.4 | JumpServer is an open source bastion host and an operation and maintenance security audit system. From 4.8.0 until 4.10.17, an authenticated user with SFTP permission … | Aug 17, 2026 |
| CVE-2026-47698 | CRITICAL | 9.8 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype … | Aug 17, 2026 |
| CVE-2026-47686 | CRITICAL | 9.9 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and AggregateError.errors but does not sanitize Error.cause, allowing … | Aug 17, 2026 |
| CVE-2026-47683 | UNKNOWN | — | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js does not cover Buffer.concat(list, totalLength) or Buffer.from(arrayLike) with an … | Aug 17, 2026 |
| CVE-2026-44846 | MEDIUM | 6.2 | JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, a user with the users.invite_user permission can … | Aug 17, 2026 |
| CVE-2026-44845 | MEDIUM | 6.7 | JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an authenticated administrator with Applet Host management … | Aug 17, 2026 |
| CVE-2026-40506 | MEDIUM | 6.5 | OpenEMR before 8.2.0 contains a path traversal vulnerability in the standard_tables_manage.php interface where the db GET parameter is passed without validation to temp_dir_cleanup(), which joins … | Aug 17, 2026 |
| CVE-2026-39255 | CRITICAL | 9.8 | Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, dup_wcs components | Aug 17, 2026 |
| CVE-2026-39254 | CRITICAL | 9.8 | Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, CxAudioHidDevice::DeviceGetDescriptionString components | Aug 17, 2026 |
| CVE-2026-35219 | UNKNOWN | — | Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, packages/server/src/automations/steps/zapier.ts, packages/server/src/automations/steps/n8n.ts, packages/server/src/automations/steps/slack.ts, and packages/server/src/automations/steps/discord.ts use node-fetch on user-provided URLs without the … | Aug 17, 2026 |
| CVE-2026-34789 | HIGH | 7.0 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/PropertyPythonObject.cpp in PropertyPythonObject::Restore() passes the attacker-controlled module attribute from serialized PropertyPythonObject XML … | Aug 17, 2026 |
| CVE-2026-34399 | HIGH | 7.8 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCAD's BIM Workbench contains an eval() call on untrusted data from … | Aug 17, 2026 |
| CVE-2026-34398 | HIGH | 7.8 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mod/BIM/bimcommands/BimProjectManager.py in the BIM Project Manager Load Template flow passes attacker-controlled … | Aug 17, 2026 |
| CVE-2026-19589 | HIGH | 7.1 | Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system modification and could lead to … | Aug 17, 2026 |
| CVE-2026-75014 | HIGH | 7.3 | A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/get_barcode_data.php. This manipulation of the … | Aug 17, 2026 |
| CVE-2026-75013 | MEDIUM | 6.5 | A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation results in null pointer dereference. The … | Aug 17, 2026 |
| CVE-2026-75012 | MEDIUM | 6.5 | A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component … | Aug 17, 2026 |
| CVE-2026-74234 | HIGH | 7.7 | Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaScript execution in a victim's browser by embedding a Mermaid block … | Aug 17, 2026 |