Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48678
Total
3911
Critical
14443
High
14141
Medium
CVE ID Severity Score Description Published
CVE-2026-16455 UNKNOWN In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged … Aug 13, 2026
CVE-2026-12263 HIGH 8.8 Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation. Aug 13, 2026
CVE-2026-59507 CRITICAL 9.3 CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control Aug 13, 2026
CVE-2026-59506 CRITICAL 9.3 CWE-306: Missing Authentication for Critical Function Aug 13, 2026
CVE-2026-59505 HIGH 8.6 CWE-284: Improper Access Control Aug 13, 2026
CVE-2026-59504 CRITICAL 9.1 CWE-602: Client-Side Enforcement of Server-Side Security Aug 13, 2026
CVE-2026-59503 CRITICAL 9.1 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor Aug 13, 2026
CVE-2026-59502 MEDIUM 5.3 CWE-203: Observable Discrepancy Aug 13, 2026
CVE-2026-59501 HIGH 8.2 CWE-284: Improper Access Control Aug 13, 2026
CVE-2026-59500 CRITICAL 10.0 CWE-287: Improper Authentication Aug 13, 2026
CVE-2026-59499 HIGH 8.6 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor Aug 13, 2026
CVE-2026-19484 HIGH 7.5 @fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop by sending a multipart … Aug 13, 2026
CVE-2026-11970 UNKNOWN This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758. Aug 13, 2026
CVE-2026-19696 MEDIUM 6.6 Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows Aug 13, 2026
CVE-2026-19695 MEDIUM 4.7 Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service Aug 13, 2026
CVE-2026-19694 MEDIUM 4.7 TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service Aug 13, 2026
CVE-2026-19481 HIGH 7.5 @fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a … Aug 13, 2026
CVE-2026-16459 UNKNOWN Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to … Aug 13, 2026
CVE-2026-16458 UNKNOWN Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts … Aug 13, 2026
CVE-2026-15413 CRITICAL 10.0 The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by … Aug 13, 2026
CVE-2026-14332 MEDIUM 5.4 The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its store-management … Aug 13, 2026
CVE-2026-14298 MEDIUM 6.5 Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit resource consumption when processing certain user-supplied input, … Aug 13, 2026
CVE-2026-3639 MEDIUM 6.4 The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in all versions up … Aug 13, 2026
CVE-2026-11840 HIGH 8.8 Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection. Aug 13, 2026
CVE-2026-18622 MEDIUM 4.7 Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into … Aug 13, 2026