Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48124
Total
3850
Critical
14244
High
13921
Medium
CVE ID Severity Score Description Published
CVE-2026-14213 LOW 3.7 The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being … Aug 13, 2026
CVE-2026-14182 CRITICAL 9.8 The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an … Aug 13, 2026
CVE-2026-13610 UNKNOWN The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged … Aug 13, 2026
CVE-2026-13328 UNKNOWN The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is also exposed to … Aug 13, 2026
CVE-2026-72506 MEDIUM 5.4 VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed … Aug 13, 2026
CVE-2026-19182 MEDIUM 4.3 An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authenticated user (ROLE_REST) to acknowledge, escalate, or … Aug 13, 2026
CVE-2026-19135 MEDIUM 5.4 A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafted expression to the … Aug 13, 2026
CVE-2026-18728 MEDIUM 6.5 A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a … Aug 13, 2026
CVE-2026-0301 UNKNOWN An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive … Aug 13, 2026
CVE-2026-0299 UNKNOWN Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and … Aug 13, 2026
CVE-2026-0298 UNKNOWN An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which … Aug 13, 2026
CVE-2026-0297 UNKNOWN A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system … Aug 13, 2026
CVE-2026-0296 UNKNOWN Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN … Aug 13, 2026
CVE-2026-0295 UNKNOWN A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The … Aug 13, 2026
CVE-2026-0294 UNKNOWN A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute … Aug 13, 2026
CVE-2026-0293 UNKNOWN A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized … Aug 13, 2026
CVE-2026-0292 UNKNOWN An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, … Aug 13, 2026
CVE-2026-0291 UNKNOWN An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low … Aug 13, 2026
CVE-2026-0290 UNKNOWN An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data. Aug 13, 2026
CVE-2026-0289 UNKNOWN A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls. Aug 13, 2026
CVE-2026-50544 MEDIUM 6.3 NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default install, the file at `src/platform/windows/misc.cpp` … Aug 13, 2026
CVE-2026-49819 CRITICAL 9.8 UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as … Aug 13, 2026
CVE-2026-49473 HIGH 8.8 @cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before … Aug 13, 2026
CVE-2026-48791 LOW 2.0 sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed verification of the integrated (Rekor entry) time) against the Fulcio … Aug 13, 2026
CVE-2026-46688 UNKNOWN The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, an unauthenticated request can be made to … Aug 13, 2026