Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48624
Total
3905
Critical
14425
High
14119
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-19293 | HIGH | 8.8 | SMP security request (from peripheral) does not include the maximum encryption key size supported. Using a key with less than the maximum keysize makes brute-forcing … | Aug 13, 2026 |
| CVE-2026-19292 | HIGH | 8.8 | Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked … | Aug 13, 2026 |
| CVE-2026-19291 | HIGH | 8.8 | Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below. | Aug 13, 2026 |
| CVE-2026-16101 | HIGH | 8.8 | Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below | Aug 13, 2026 |
| CVE-2026-15994 | HIGH | 7.0 | During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated … | Aug 13, 2026 |
| CVE-2026-14456 | HIGH | 7.5 | Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue … | Aug 13, 2026 |
| CVE-2026-14256 | MEDIUM | 4.7 | ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstances, could allow a local authenticated user to cause a … | Aug 13, 2026 |
| CVE-2026-12036 | HIGH | 7.1 | An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to … | Aug 13, 2026 |
| CVE-2026-73403 | MEDIUM | 5.3 | Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions. | Aug 13, 2026 |
| CVE-2026-73401 | MEDIUM | 5.3 | Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions. | Aug 13, 2026 |
| CVE-2026-73357 | MEDIUM | 6.5 | Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions. | Aug 13, 2026 |
| CVE-2026-73353 | MEDIUM | 5.3 | Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions. | Aug 13, 2026 |
| CVE-2026-73349 | MEDIUM | 5.3 | Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. | Aug 13, 2026 |
| CVE-2026-73346 | HIGH | 7.6 | Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions. | Aug 13, 2026 |
| CVE-2026-73344 | MEDIUM | 5.9 | Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. | Aug 13, 2026 |
| CVE-2026-73340 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions. | Aug 13, 2026 |
| CVE-2026-73188 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-13610. | Aug 13, 2026 |
| CVE-2026-67991 | HIGH | 7.5 | crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name … | Aug 13, 2026 |
| CVE-2026-67990 | MEDIUM | 5.4 | basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logged-in user's browser to … | Aug 13, 2026 |
| CVE-2026-67986 | HIGH | 8.4 | amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a … | Aug 13, 2026 |
| CVE-2026-66704 | HIGH | 7.2 | Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. | Aug 13, 2026 |
| CVE-2026-66700 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions. | Aug 13, 2026 |
| CVE-2026-66698 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions. | Aug 13, 2026 |
| CVE-2026-66697 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions. | Aug 13, 2026 |
| CVE-2026-66693 | MEDIUM | 6.5 | Subscriber Broken Access Control in Motors <= 1.4.113 versions. | Aug 13, 2026 |