Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48678
Total
3911
Critical
14443
High
14141
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-16455 | UNKNOWN | — | In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged … | Aug 13, 2026 |
| CVE-2026-12263 | HIGH | 8.8 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation. | Aug 13, 2026 |
| CVE-2026-59507 | CRITICAL | 9.3 | CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control | Aug 13, 2026 |
| CVE-2026-59506 | CRITICAL | 9.3 | CWE-306: Missing Authentication for Critical Function | Aug 13, 2026 |
| CVE-2026-59505 | HIGH | 8.6 | CWE-284: Improper Access Control | Aug 13, 2026 |
| CVE-2026-59504 | CRITICAL | 9.1 | CWE-602: Client-Side Enforcement of Server-Side Security | Aug 13, 2026 |
| CVE-2026-59503 | CRITICAL | 9.1 | CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor | Aug 13, 2026 |
| CVE-2026-59502 | MEDIUM | 5.3 | CWE-203: Observable Discrepancy | Aug 13, 2026 |
| CVE-2026-59501 | HIGH | 8.2 | CWE-284: Improper Access Control | Aug 13, 2026 |
| CVE-2026-59500 | CRITICAL | 10.0 | CWE-287: Improper Authentication | Aug 13, 2026 |
| CVE-2026-59499 | HIGH | 8.6 | CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | Aug 13, 2026 |
| CVE-2026-19484 | HIGH | 7.5 | @fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop by sending a multipart … | Aug 13, 2026 |
| CVE-2026-11970 | UNKNOWN | — | This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758. | Aug 13, 2026 |
| CVE-2026-19696 | MEDIUM | 6.6 | Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows | Aug 13, 2026 |
| CVE-2026-19695 | MEDIUM | 4.7 | Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service | Aug 13, 2026 |
| CVE-2026-19694 | MEDIUM | 4.7 | TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service | Aug 13, 2026 |
| CVE-2026-19481 | HIGH | 7.5 | @fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser by sending a … | Aug 13, 2026 |
| CVE-2026-16459 | UNKNOWN | — | Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to … | Aug 13, 2026 |
| CVE-2026-16458 | UNKNOWN | — | Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts … | Aug 13, 2026 |
| CVE-2026-15413 | CRITICAL | 10.0 | The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by … | Aug 13, 2026 |
| CVE-2026-14332 | MEDIUM | 5.4 | The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its store-management … | Aug 13, 2026 |
| CVE-2026-14298 | MEDIUM | 6.5 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit resource consumption when processing certain user-supplied input, … | Aug 13, 2026 |
| CVE-2026-3639 | MEDIUM | 6.4 | The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in all versions up … | Aug 13, 2026 |
| CVE-2026-11840 | HIGH | 8.8 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection. | Aug 13, 2026 |
| CVE-2026-18622 | MEDIUM | 4.7 | Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into … | Aug 13, 2026 |