Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48851
Total
3923
Critical
14488
High
14228
Medium
CVE ID Severity Score Description Published
CVE-2026-13177 UNKNOWN The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing users with contributor-level access and above to read other … Aug 12, 2026
CVE-2026-13171 HIGH 8.2 The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticated users to create WordPress user accounts … Aug 12, 2026
CVE-2026-13168 MEDIUM 6.5 The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users with contributor-level access and above to read other … Aug 12, 2026
CVE-2026-12976 MEDIUM 6.5 The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-assistant requests against that course's lesson … Aug 12, 2026
CVE-2026-64954 HIGH 8.2 Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this … Aug 12, 2026
CVE-2026-12235 MEDIUM 6.3 The Linkable Loadable Extensions (llext) subsystem mis-handles PLT/RELA relocation entries when linking a relocatable (partially-linked) ELF extension. In llext_link_plt() (subsys/llext/llext_link.c), the relocatable branch (tgt != … Aug 12, 2026
CVE-2026-12234 HIGH 7.8 The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c snapshot the caller-supplied struct net_msghdr into a kernel-side copy with k_usermode_from_copy(), but then re-read the still-live … Aug 12, 2026
CVE-2026-12233 MEDIUM 5.9 The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its credential-store mutex as a plain zero-filled static struct k_mutex credential_lock; and never called k_mutex_init() on it. … Aug 12, 2026
CVE-2026-12232 MEDIUM 6.1 The Intel ALH digital-audio-interface driver function dai_alh_get_properties() in drivers/dai/intel/alh/alh.c used a caller-supplied int stream_id with no range validation. The value indexes the fixed-size static const … Aug 12, 2026
CVE-2025-15687 MEDIUM 4.3 A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF Diameter Gx Credit-Control-Answer Handler. The … Aug 12, 2026
CVE-2026-9318 MEDIUM 5.4 tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedding malicious … Aug 12, 2026
CVE-2026-19588 MEDIUM 6.5 Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. Aug 12, 2026
CVE-2026-19587 MEDIUM 6.5 Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation. Aug 12, 2026
CVE-2026-18961 HIGH 8.1 The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider … Aug 12, 2026
CVE-2025-15686 MEDIUM 4.3 A vulnerability has been found in Open5GS up to 2.7.6. Affected by this issue is the function fd_msg_sess_get of the component HSS Service. Such manipulation … Aug 12, 2026
CVE-2025-15685 MEDIUM 6.3 A flaw has been found in Open5GS up to 2.7.1. Affected by this vulnerability is an unknown functionality of the component freeDiameter. This manipulation causes … Aug 12, 2026
CVE-2025-15684 MEDIUM 5.3 A vulnerability was detected in Open5GS up to 2.7.6. Affected is the function diam_log_func of the file lib/diameter/common/init.c of the component CER Handler. The manipulation … Aug 12, 2026
CVE-2026-73122 HIGH 7.7 A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster … Aug 12, 2026
CVE-2026-72526 CRITICAL 9.9 A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. … Aug 12, 2026
CVE-2026-70398 CRITICAL 9.6 A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a … Aug 12, 2026
CVE-2026-66878 HIGH 7.7 A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By … Aug 12, 2026
CVE-2026-64927 MEDIUM 6.4 A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known … Aug 12, 2026
CVE-2026-6484 HIGH 8.2 In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution. Aug 12, 2026
CVE-2026-68450 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: btrfs: free mapping node on duplicate reloc root insert __add_reloc_root() allocates a mapping_node before inserting … Aug 12, 2026
CVE-2026-68449 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning The hand-rolled bit-scanning loop in … Aug 12, 2026