Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

47587
Total
3849
Critical
14223
High
13906
Medium
CVE ID Severity Score Description Published
CVE-2026-19884 UNKNOWN In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the folder first. … Aug 14, 2026
CVE-2026-19837 LOW 2.7 A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/search of the component Customer Search. … Aug 14, 2026
CVE-2026-19836 MEDIUM 4.3 A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/customers/view of … Aug 14, 2026
CVE-2026-19835 LOW 3.8 A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. … Aug 14, 2026
CVE-2026-19834 MEDIUM 4.7 A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonation … Aug 14, 2026
CVE-2026-16772 HIGH 8.1 In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges. This … Aug 14, 2026
CVE-2026-13198 UNKNOWN Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the event notification functionality of KUNBUS piControl … Aug 14, 2026
CVE-2026-13197 UNKNOWN Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the configuration and process-image management functionality of … Aug 14, 2026
CVE-2026-13196 UNKNOWN Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated … Aug 14, 2026
CVE-2026-13002 MEDIUM 4.4 A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the … Aug 14, 2026
CVE-2026-69101 HIGH 7.7 Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by … Aug 14, 2026
CVE-2026-58224 MEDIUM 6.5 A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets … Aug 14, 2026
CVE-2026-19880 UNKNOWN Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender … Aug 14, 2026
CVE-2026-19879 MEDIUM 5.3 A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method performs a silent narrowing cast from … Aug 14, 2026
CVE-2026-73633 HIGH 7.5 Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the … Aug 14, 2026
CVE-2026-53472 MEDIUM 6.3 A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialUrl` field allows an authenticated attacker to store a malicious `javascript:` URL. When a victim … Aug 14, 2026
CVE-2026-1621 MEDIUM 5.3 Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality allows Exploitation of Trusted Identifiers. This issue affects E-Municipality: from 20251127 before 20260204. Aug 14, 2026
CVE-2026-19871 UNKNOWN Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee … Aug 14, 2026
CVE-2026-19830 MEDIUM 5.3 A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of the file /etc/bftpd.conf of the component bftpd. The manipulation of the … Aug 14, 2026
CVE-2026-19829 MEDIUM 4.3 A security flaw has been discovered in 648540858 wvp-GB28181-pro 2.7.4-20260107. This vulnerability affects unknown code of the file LogController.java of the component Log File Download … Aug 14, 2026
CVE-2026-19828 MEDIUM 6.3 A vulnerability was identified in 648540858 wvp-GB28181-pro 2.7.4-20260107. This affects an unknown part of the file PlayController.java of the component Snapshot Endpoint. The manipulation of … Aug 14, 2026
CVE-2026-19827 MEDIUM 5.3 A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStream of the file /admin/controller/JobLogController.java of the component logDetailCat Endpoint. … Aug 14, 2026
CVE-2026-19768 HIGH 8.1 Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings … Aug 14, 2026
CVE-2026-73673 HIGH 8.8 Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authentication … Aug 14, 2026
CVE-2026-19870 UNKNOWN Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to … Aug 14, 2026