Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48891
Total
3931
Critical
14494
High
14248
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-72610 | MEDIUM | 4.3 | A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the borrowers => edit_borrowers permission to cause a … | Aug 11, 2026 |
| CVE-2026-72609 | HIGH | 7.1 | An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the acquisition => order_receive permission to read arbitrary database … | Aug 11, 2026 |
| CVE-2026-72608 | MEDIUM | 6.5 | A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => label_creator permission to execute arbitrary … | Aug 11, 2026 |
| CVE-2026-72607 | HIGH | 7.1 | A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => items_batchmod permission to read arbitrary … | Aug 11, 2026 |
| CVE-2026-72606 | HIGH | 7.5 | A server-side request forgery vulnerability in Pinry through 2.1.13 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or external … | Aug 11, 2026 |
| CVE-2026-72605 | HIGH | 7.5 | A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is … | Aug 11, 2026 |
| CVE-2026-72604 | MEDIUM | 6.5 | A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete arbitrary files on the server via the admin panel file … | Aug 11, 2026 |
| CVE-2026-72603 | CRITICAL | 9.9 | An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp … | Aug 11, 2026 |
| CVE-2026-72602 | HIGH | 7.5 | A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths via the local-repository … | Aug 11, 2026 |
| CVE-2026-72601 | HIGH | 7.5 | A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissions including personally identifiable information via the admin … | Aug 11, 2026 |
| CVE-2026-72600 | HIGH | 7.5 | A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing customer PII via the … | Aug 11, 2026 |
| CVE-2026-72599 | CRITICAL | 9.8 | An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. The parameter is … | Aug 11, 2026 |
| CVE-2026-72598 | MEDIUM | 6.5 | A server-side request forgery vulnerability in Apioo Fusio 8.8.3 allows authenticated consumer-role users to make the server issue HTTP requests to internal network addresses by … | Aug 11, 2026 |
| CVE-2026-72597 | MEDIUM | 6.5 | A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with a free self-registered account to probe internal network services via … | Aug 11, 2026 |
| CVE-2026-72596 | HIGH | 8.1 | A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete posts owned by other users. The post model permissible() … | Aug 11, 2026 |
| CVE-2026-72595 | HIGH | 8.1 | A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update ticket records belonging to other teams via the … | Aug 11, 2026 |
| CVE-2026-72563 | HIGH | 8.1 | A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to overwrite lead records belonging to other teams via the … | Aug 11, 2026 |
| CVE-2026-72562 | HIGH | 8.8 | An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via the DataObject grid id column filter. … | Aug 11, 2026 |
| CVE-2026-72561 | HIGH | 8.8 | A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfigure the platform global OIDC/SSO settings via … | Aug 11, 2026 |
| CVE-2026-72560 | MEDIUM | 6.5 | A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTION_ENABLED is set to false by default. The import-from-URL endpoint fetches any … | Aug 11, 2026 |
| CVE-2026-72559 | MEDIUM | 5.4 | A stored cross-site scripting vulnerability in HortusFox 5.9 allows authenticated workspace members to inject persistent JavaScript into plant notes via Parsedown rendered without safe mode. … | Aug 11, 2026 |
| CVE-2026-72558 | HIGH | 8.8 | An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE clause. The clause concatenates … | Aug 11, 2026 |
| CVE-2026-72557 | HIGH | 8.8 | An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP scripts via the asset upload … | Aug 11, 2026 |
| CVE-2026-72556 | HIGH | 8.8 | A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by exploiting a broken permission check in the Filter … | Aug 11, 2026 |
| CVE-2026-72555 | HIGH | 8.1 | A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.roles_active flag defaults to false, causing all permission checks on … | Aug 11, 2026 |