Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

28438
Total
2190
Critical
8535
High
8856
Medium
CVE ID Severity Score Description Published
CVE-2026-44887 CRITICAL 9.8 Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's web-based configuration editor allows arbitrary Python code to be … May 27, 2026
CVE-2026-44886 UNKNOWN Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. From 2024-06-29 to before 2026-05-07, the web application endpoint is vulnerable to SQL … May 27, 2026
CVE-2026-44724 HIGH 7.8 systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when … May 27, 2026
CVE-2026-44681 MEDIUM 6.1 Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and … May 27, 2026
CVE-2026-44590 CRITICAL 9.3 Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via … May 27, 2026
CVE-2026-42877 MEDIUM 5.4 FacturaScripts is an open source accounting and invoicing software. In 2025.92 and earlier, a stored Cross-Site Scripting (XSS) vulnerability exists in the product search modal … May 27, 2026
CVE-2026-42197 HIGH 8.7 RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a stored cross-site scripting vulnerability that allows any enrolled student to execute arbitrary … May 27, 2026
CVE-2026-33552 LOW 3.7 Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control. May 27, 2026
CVE-2026-8716 MEDIUM 4.3 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain … May 27, 2026
CVE-2026-6713 MEDIUM 5.3 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain … May 27, 2026
CVE-2026-5296 MEDIUM 4.3 GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that when foundational … May 27, 2026
CVE-2026-4868 HIGH 8.2 GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under certain … May 27, 2026
CVE-2026-45046 MEDIUM 5.5 Gryph provides a security layer for AI coding agents. Prior to 0.7.0, Gryph implements logging levels that determine what content is logged to a local … May 27, 2026
CVE-2026-44635 HIGH 7.5 Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does not escape JSON-path metacharacters (., [, ], *, **, ?). When … May 27, 2026
CVE-2026-42879 MEDIUM 6.3 FacturaScripts is an open source accounting and invoicing software. In 2025.81 and earlier, an authenticated unrestricted file upload vulnerability exists in FacturaScripts' product image upload … May 27, 2026
CVE-2026-42878 MEDIUM 5.3 FacturaScripts is an open source accounting and invoicing software. Prior to v2026, an unauthenticated information disclosure vulnerability in the Installer controller allows any remote attacker … May 27, 2026
CVE-2026-2601 MEDIUM 4.3 GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain … May 27, 2026
CVE-2026-1402 MEDIUM 6.5 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain … May 27, 2026
CVE-2026-5509 UNKNOWN An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an administrator to execute arbitrary system commands through … May 27, 2026
CVE-2026-4392 MEDIUM 5.3 A vulnerability was detected in TeamSpeak 3 Server up to 3.13.7. This issue affects some unknown processing of the component clientek Handshake Handler. Performing a … May 27, 2026
CVE-2026-4391 MEDIUM 5.3 A security vulnerability has been detected in TeamSpeak 3 Server up to 3.13.7. This vulnerability affects unknown code of the component ECC Key Parser. Such … May 27, 2026
CVE-2026-4390 MEDIUM 5.4 A weakness has been identified in TeamSpeak 3 Server up to 3.13.7. This affects the function process_resend_queue of the component Connection State Management. This manipulation … May 27, 2026
CVE-2026-48153 HIGH 8.5 Budibase is an open-source low-code platform. Prior to 3.39.0, fetchToken in the OAuth2 SDK makes a POST to a builder-supplied URL with plain node-fetch, skipping … May 27, 2026
CVE-2026-48152 HIGH 8.1 Budibase is an open-source low-code platform. Prior to 3.39.0, the single-datasource GET and PUT routes are guarded by generic TABLE READ, not by Builder/Admin permission … May 27, 2026
CVE-2026-48151 HIGH 7.5 Budibase is an open-source low-code platform. Prior to 3.39.0, the webhook schema-building endpoint is registered under builderRoutes, but the generic authorization middleware skips authorization for … May 27, 2026