Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42028
Total
3422
Critical
12413
High
12340
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2024-35585 | HIGH | 8.6 | Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication. | Sep 02, 2026 |
| CVE-2026-3851 | MEDIUM | 6.4 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's legacy JSON format in all versions up to, and … | Sep 02, 2026 |
| CVE-2026-19754 | UNKNOWN | — | Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify formula fields can provide … | Sep 02, 2026 |
| CVE-2026-84442 | MEDIUM | 4.4 | A vulnerability was identified in MapQuest Get Directions App 10.16.1 on Android. This vulnerability affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component … | Sep 02, 2026 |
| CVE-2026-84441 | HIGH | 7.3 | A security vulnerability has been detected in Piwigo up to 16.3.0. Affected by this issue is some unknown functionality of the file i.php of the … | Sep 02, 2026 |
| CVE-2026-14982 | HIGH | 8.1 | The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all … | Sep 02, 2026 |
| CVE-2026-14957 | HIGH | 7.5 | In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, … | Sep 02, 2026 |
| CVE-2026-84715 | HIGH | 8.8 | FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with … | Sep 02, 2026 |
| CVE-2026-84485 | HIGH | 7.5 | APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can … | Sep 02, 2026 |
| CVE-2026-84484 | HIGH | 7.5 | ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV … | Sep 02, 2026 |
| CVE-2026-84438 | LOW | 3.5 | A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affects an unknown function of the file catalog/controller/account/edit.php of the component Autocomplete Workflow. This manipulation of the … | Sep 02, 2026 |
| CVE-2026-84437 | LOW | 3.5 | A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted element is an unknown function of the file catalog/controller/account/address.php of the component Autocomplete Workflow. The manipulation … | Sep 02, 2026 |
| CVE-2026-84431 | MEDIUM | 4.4 | A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.mobile. Performing a … | Sep 02, 2026 |
| CVE-2026-82968 | MEDIUM | 6.4 | A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their … | Sep 02, 2026 |
| CVE-2026-84702 | HIGH | 7.5 | facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in … | Sep 02, 2026 |
| CVE-2026-84701 | MEDIUM | 5.4 | NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store malicious HTML with event handlers. Attackers … | Sep 02, 2026 |
| CVE-2026-84700 | HIGH | 8.6 | PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client … | Sep 02, 2026 |
| CVE-2026-84699 | CRITICAL | 9.1 | Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and … | Sep 02, 2026 |
| CVE-2026-84698 | MEDIUM | 6.5 | PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_bench command that writes a four-byte block number into a user-supplied sized allocation. Attackers can … | Sep 02, 2026 |
| CVE-2026-84697 | MEDIUM | 5.3 | Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv4-translated IPv6 prefix, allowing server-side request forgery to … | Sep 02, 2026 |
| CVE-2026-84696 | HIGH | 8.2 | Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass … | Sep 02, 2026 |
| CVE-2026-84695 | HIGH | 8.7 | BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. … | Sep 02, 2026 |
| CVE-2026-84694 | HIGH | 8.8 | Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell … | Sep 02, 2026 |
| CVE-2026-84430 | MEDIUM | 6.3 | A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability affects the function update of the file app/home/controller/Index.php of the component edit_personal … | Sep 02, 2026 |
| CVE-2026-84427 | MEDIUM | 4.3 | A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affected is an unknown function of the file agent/tools/bash/bash.py of the component Bash Tool. Executing … | Sep 02, 2026 |