Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48851
Total
3923
Critical
14488
High
14228
Medium
CVE ID Severity Score Description Published
CVE-2026-11325 HIGH 8.8 Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/index.ts` reachable from certain … Aug 12, 2026
CVE-2026-68868 MEDIUM 6.5 The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` … Aug 12, 2026
CVE-2026-67284 UNKNOWN Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated users could perform various file-related operations (read, … Aug 12, 2026
CVE-2026-64955 MEDIUM 6.1 When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. Velociraptor fails to … Aug 12, 2026
CVE-2026-64952 MEDIUM 6.5 The hunt_delete() VQL function allows deleting hunts. Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned to the "investigator" role) instead of the "DELETE_RESULTS" … Aug 12, 2026
CVE-2026-64951 LOW 3.5 A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic occurs which may … Aug 12, 2026
CVE-2026-18663 MEDIUM 5.9 A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS … Aug 12, 2026
CVE-2026-18652 MEDIUM 4.9 Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI … Aug 12, 2026
CVE-2026-67283 UNKNOWN Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform various file-related operations (read, … Aug 12, 2026
CVE-2026-67282 UNKNOWN Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend … Aug 12, 2026
CVE-2026-19566 HIGH 7.5 Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths. The _encode method accepts any prefix length … Aug 12, 2026
CVE-2026-19426 HIGH 8.2 POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the system. Aug 12, 2026
CVE-2025-41771 MEDIUM 4.3 An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerable to SQL injection. The vulnerability affects a … Aug 12, 2026
CVE-2025-41770 HIGH 7.5 An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents … Aug 12, 2026
CVE-2025-41769 CRITICAL 9.8 The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability … Aug 12, 2026
CVE-2026-66659 CRITICAL 9.3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection. This issue affects Tablesome … Aug 12, 2026
CVE-2026-19594 HIGH 8.1 Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded … Aug 12, 2026
CVE-2026-19217 MEDIUM 5.4 The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTML tag before outputting it, which … Aug 12, 2026
CVE-2026-19073 MEDIUM 5.3 The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and … Aug 12, 2026
CVE-2026-19052 MEDIUM 4.3 The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX actions, and the nonce they rely on is … Aug 12, 2026
CVE-2026-19050 MEDIUM 6.4 The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capability or nonce of the requester, … Aug 12, 2026
CVE-2026-18962 MEDIUM 4.3 The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload into the album they target … Aug 12, 2026
CVE-2026-18943 MEDIUM 6.5 The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allowing users with a role as … Aug 12, 2026
CVE-2026-18789 HIGH 7.5 The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated attackers to trigger a server-side … Aug 12, 2026
CVE-2026-18474 HIGH 8.6 The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a … Aug 12, 2026