Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

47022
Total
3783
Critical
14020
High
13725
Medium
CVE ID Severity Score Description Published
CVE-2026-12128 MEDIUM 5.3 The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` parameter in all versions up to, and … Aug 15, 2026
CVE-2026-74250 MEDIUM 6.3 In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface. Aug 14, 2026
CVE-2026-74247 MEDIUM 4.2 A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability … Aug 14, 2026
CVE-2026-74245 MEDIUM 5.9 A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without … Aug 14, 2026
CVE-2026-74244 MEDIUM 5.9 A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted … Aug 14, 2026
CVE-2026-74243 MEDIUM 6.5 A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to … Aug 14, 2026
CVE-2026-74242 MEDIUM 5.3 A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can … Aug 14, 2026
CVE-2026-74241 MEDIUM 4.8 A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the … Aug 14, 2026
CVE-2026-74240 MEDIUM 5.4 A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related … Aug 14, 2026
CVE-2026-63650 UNKNOWN OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field Aug 14, 2026
CVE-2026-63649 UNKNOWN The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and … Aug 14, 2026
CVE-2026-18932 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 14, 2026
CVE-2026-73683 HIGH 8.1 Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim validation … Aug 14, 2026
CVE-2026-69414 HIGH 7.8 Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are … Aug 14, 2026
CVE-2026-74248 MEDIUM 4.3 OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent … Aug 14, 2026
CVE-2026-73682 HIGH 8.8 Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url handling that allows authenticated users holding the Manager … Aug 14, 2026
CVE-2026-71570 UNKNOWN Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_icagenda` only could enumerate … Aug 14, 2026
CVE-2026-67366 UNKNOWN Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the frontend are callable without … Aug 14, 2026
CVE-2026-50523 HIGH 7.8 Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally. Aug 14, 2026
CVE-2026-73680 HIGH 8.8 Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute … Aug 14, 2026
CVE-2026-71571 UNKNOWN Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 - Backend operators with permissions to access iCagenda could … Aug 14, 2026
CVE-2026-67365 UNKNOWN Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session, … Aug 14, 2026
CVE-2026-64887 UNKNOWN Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack. This issue affects Airwall: before 4.1. Aug 14, 2026
CVE-2026-39925 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 14, 2026
CVE-2026-34492 UNKNOWN External control of file name or path vulnerability in Johnson Controls Airwall allows : File Manipulation. This issue affects Airwall: before 4.1. Aug 14, 2026