Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

28297
Total
2180
Critical
8507
High
8806
Medium
CVE ID Severity Score Description Published
CVE-2026-44651 UNKNOWN SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. … May 29, 2026
CVE-2026-44650 CRITICAL 9.1 SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. … May 29, 2026
CVE-2026-44649 CRITICAL 9.8 SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. … May 29, 2026
CVE-2026-44648 HIGH 7.5 SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. … May 29, 2026
CVE-2026-44611 MEDIUM 5.4 Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks. May 29, 2026
CVE-2026-44518 MEDIUM 5.3 liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS … May 29, 2026
CVE-2026-42951 MEDIUM 5.4 An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes. May 29, 2026
CVE-2026-42941 HIGH 8.3 The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change. May 29, 2026
CVE-2026-42929 HIGH 8.3 Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials. May 29, 2026
CVE-2026-40425 MEDIUM 5.7 The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password. May 29, 2026
CVE-2026-7786 CRITICAL 9.8 Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credentials embedded in the firmware image. These credentials can … May 29, 2026
CVE-2026-6824 HIGH 8.4 A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers … May 29, 2026
CVE-2026-5768 HIGH 8.8 The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range … May 29, 2026
CVE-2026-5386 CRITICAL 9.1 The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password … May 29, 2026
CVE-2026-47179 HIGH 7.7 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns the contents of any Docker Compose include directive … May 29, 2026
CVE-2026-47125 HIGH 8.8 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/environments/{id}/templates/variables endpoint, which writes the system-wide .env.global file … May 29, 2026
CVE-2026-45668 UNKNOWN Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malicious ZIP archive imported with … May 29, 2026
CVE-2026-45661 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows … May 29, 2026
CVE-2026-45660 MEDIUM 5.4 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image proxy's URL validation could be bypassed … May 29, 2026
CVE-2026-45633 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. … May 29, 2026
CVE-2026-45632 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, … May 29, 2026
CVE-2026-45631 CRITICAL 10.0 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-secret-123456789") lets an unauthenticated attacker forge … May 29, 2026
CVE-2026-45630 CRITICAL 9.0 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner … May 29, 2026
CVE-2026-45629 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any … May 29, 2026
CVE-2026-45628 CRITICAL 9.6 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template literals and executes them … May 29, 2026