Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48851
Total
3923
Critical
14488
High
14228
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-47229 | MEDIUM | 5.4 | Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm_csrf_token` on every state-changing branch except `enable`. The `enable` case loads … | Aug 12, 2026 |
| CVE-2026-47228 | MEDIUM | 5.2 | Admidio is an open-source user management solution. `modules/registration.php` mode `send_login` regenerates a random password for `user_uuid_assigned`, stores its bcrypt hash in `adm_users.usr_password`, and emails the … | Aug 12, 2026 |
| CVE-2026-47227 | MEDIUM | 6.5 | Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (`ANN`, `EVT`, `ROL`, `USF`, …) corresponds to a module the actor … | Aug 12, 2026 |
| CVE-2026-16999 | MEDIUM | 6.3 | Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linking. This issue affects UYAP Document … | Aug 12, 2026 |
| CVE-2025-59327 | UNKNOWN | — | In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity … | Aug 12, 2026 |
| CVE-2025-59326 | UNKNOWN | — | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for unsigned code to be executed … | Aug 12, 2026 |
| CVE-2025-59325 | UNKNOWN | — | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allowing for the offline recovery of secrets and cryptographic details. | Aug 12, 2026 |
| CVE-2026-71408 | MEDIUM | 5.3 | A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow … | Aug 12, 2026 |
| CVE-2026-71407 | MEDIUM | 5.6 | A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR … | Aug 12, 2026 |
| CVE-2026-70468 | HIGH | 8.1 | A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, … | Aug 12, 2026 |
| CVE-2026-70467 | LOW | 3.8 | A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all … | Aug 12, 2026 |
| CVE-2026-70466 | MEDIUM | 5.3 | A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, … | Aug 12, 2026 |
| CVE-2026-57858 | HIGH | 8.9 | Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript … | Aug 12, 2026 |
| CVE-2026-53996 | HIGH | 7.0 | NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unprivileged local attackers to invoke the HDAUDIO_FGRP_SETCONFIG ioctl without elevated permissions by … | Aug 12, 2026 |
| CVE-2026-47226 | MEDIUM | 6.5 | Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload rights on any one folder can permanently delete … | Aug 12, 2026 |
| CVE-2026-26035 | CRITICAL | 9.8 | An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb … | Aug 12, 2026 |
| CVE-2026-70560 | MEDIUM | 5.4 | Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-privileged authenticated attackers to inject arbitrary HTML and script … | Aug 12, 2026 |
| CVE-2026-70465 | HIGH | 8.1 | A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an … | Aug 12, 2026 |
| CVE-2026-18044 | LOW | 3.7 | The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later uses to address the message sent … | Aug 12, 2026 |
| CVE-2026-17008 | MEDIUM | 5.3 | The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and marks … | Aug 12, 2026 |
| CVE-2026-16990 | MEDIUM | 5.3 | The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-supplied payment amount, allowing unauthenticated attackers … | Aug 12, 2026 |
| CVE-2026-16747 | MEDIUM | 6.5 | The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes attacker-controlled input through shortcode execution, allowing unauthenticated … | Aug 12, 2026 |
| CVE-2026-16621 | MEDIUM | 5.3 | The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal … | Aug 12, 2026 |
| CVE-2026-15213 | MEDIUM | 5.3 | The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-transfer settlement callback: an unauthenticated request can flip an … | Aug 12, 2026 |
| CVE-2026-15045 | MEDIUM | 6.5 | The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored balance during checkout, allowing … | Aug 12, 2026 |