Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48891
Total
3931
Critical
14494
High
14248
Medium
CVE ID Severity Score Description Published
CVE-2026-72610 MEDIUM 4.3 A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the borrowers => edit_borrowers permission to cause a … Aug 11, 2026
CVE-2026-72609 HIGH 7.1 An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the acquisition => order_receive permission to read arbitrary database … Aug 11, 2026
CVE-2026-72608 MEDIUM 6.5 A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => label_creator permission to execute arbitrary … Aug 11, 2026
CVE-2026-72607 HIGH 7.1 A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => items_batchmod permission to read arbitrary … Aug 11, 2026
CVE-2026-72606 HIGH 7.5 A server-side request forgery vulnerability in Pinry through 2.1.13 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or external … Aug 11, 2026
CVE-2026-72605 HIGH 7.5 A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is … Aug 11, 2026
CVE-2026-72604 MEDIUM 6.5 A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete arbitrary files on the server via the admin panel file … Aug 11, 2026
CVE-2026-72603 CRITICAL 9.9 An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp … Aug 11, 2026
CVE-2026-72602 HIGH 7.5 A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths via the local-repository … Aug 11, 2026
CVE-2026-72601 HIGH 7.5 A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissions including personally identifiable information via the admin … Aug 11, 2026
CVE-2026-72600 HIGH 7.5 A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing customer PII via the … Aug 11, 2026
CVE-2026-72599 CRITICAL 9.8 An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. The parameter is … Aug 11, 2026
CVE-2026-72598 MEDIUM 6.5 A server-side request forgery vulnerability in Apioo Fusio 8.8.3 allows authenticated consumer-role users to make the server issue HTTP requests to internal network addresses by … Aug 11, 2026
CVE-2026-72597 MEDIUM 6.5 A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with a free self-registered account to probe internal network services via … Aug 11, 2026
CVE-2026-72596 HIGH 8.1 A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete posts owned by other users. The post model permissible() … Aug 11, 2026
CVE-2026-72595 HIGH 8.1 A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update ticket records belonging to other teams via the … Aug 11, 2026
CVE-2026-72563 HIGH 8.1 A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to overwrite lead records belonging to other teams via the … Aug 11, 2026
CVE-2026-72562 HIGH 8.8 An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via the DataObject grid id column filter. … Aug 11, 2026
CVE-2026-72561 HIGH 8.8 A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfigure the platform global OIDC/SSO settings via … Aug 11, 2026
CVE-2026-72560 MEDIUM 6.5 A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTION_ENABLED is set to false by default. The import-from-URL endpoint fetches any … Aug 11, 2026
CVE-2026-72559 MEDIUM 5.4 A stored cross-site scripting vulnerability in HortusFox 5.9 allows authenticated workspace members to inject persistent JavaScript into plant notes via Parsedown rendered without safe mode. … Aug 11, 2026
CVE-2026-72558 HIGH 8.8 An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE clause. The clause concatenates … Aug 11, 2026
CVE-2026-72557 HIGH 8.8 An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP scripts via the asset upload … Aug 11, 2026
CVE-2026-72556 HIGH 8.8 A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by exploiting a broken permission check in the Filter … Aug 11, 2026
CVE-2026-72555 HIGH 8.1 A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.roles_active flag defaults to false, causing all permission checks on … Aug 11, 2026