Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

47022
Total
3783
Critical
14020
High
13725
Medium
CVE ID Severity Score Description Published
CVE-2026-50027 CRITICAL 9.8 mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, … Aug 14, 2026
CVE-2026-49457 CRITICAL 9.1 erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The … Aug 14, 2026
CVE-2026-45699 HIGH 7.5 Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in … Aug 14, 2026
CVE-2026-19188 CRITICAL 10.0 A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature … Aug 14, 2026
CVE-2026-18403 UNKNOWN LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central … Aug 14, 2026
CVE-2025-7639 UNKNOWN The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution … Aug 14, 2026
CVE-2026-73850 UNKNOWN Emlog is an open source website building system. In 2.6.20 and earlier, there is a SQL injection vulnerability in the queryDatabase function in ai.php. Aug 14, 2026
CVE-2026-73849 CRITICAL 9.8 Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the … Aug 14, 2026
CVE-2026-73847 MEDIUM 6.8 Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a … Aug 14, 2026
CVE-2026-72970 HIGH 8.3 Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Aug 14, 2026
CVE-2026-63361 UNKNOWN LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text and name query parameters are passed … Aug 14, 2026
CVE-2026-49282 MEDIUM 5.1 Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends … Aug 14, 2026
CVE-2026-49263 UNKNOWN Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-controlled raw WASM instruction bytes through the public `cs_disasm()` and `cs_disasm_iter()` APIs. … Aug 14, 2026
CVE-2026-48528 CRITICAL 9.8 Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in … Aug 14, 2026
CVE-2026-19847 HIGH 8.8 A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so. The manipulation … Aug 14, 2026
CVE-2026-19846 HIGH 8.8 A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the … Aug 14, 2026
CVE-2026-19682 CRITICAL 9.9 A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating … Aug 14, 2026
CVE-2026-19681 CRITICAL 9.9 An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted … Aug 14, 2026
CVE-2026-19680 HIGH 7.1 A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database. Aug 14, 2026
CVE-2026-19679 HIGH 8.8 An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue. Aug 14, 2026
CVE-2026-19639 MEDIUM 4.3 An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope. Aug 14, 2026
CVE-2026-19636 MEDIUM 5.3 An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a security control. This has been … Aug 14, 2026
CVE-2026-19635 HIGH 8.8 A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with … Aug 14, 2026
CVE-2026-19631 MEDIUM 4.9 A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to … Aug 14, 2026
CVE-2026-19629 HIGH 8.1 A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group … Aug 14, 2026