Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48891
Total
3931
Critical
14494
High
14248
Medium
CVE ID Severity Score Description Published
CVE-2026-72554 MEDIUM 6.5 A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer to read ticket conversations belonging to other customers via … Aug 11, 2026
CVE-2026-72553 MEDIUM 5.4 A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persistent JavaScript into the profile fields cust_blurb and … Aug 11, 2026
CVE-2026-72552 HIGH 7.5 A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or … Aug 11, 2026
CVE-2026-72551 HIGH 8.8 A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with the Developer role to execute arbitrary OS commands by exploiting a PHP-Sandbox … Aug 11, 2026
CVE-2026-72550 CRITICAL 9.8 An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to execute arbitrary SQL statements via the photo-view order parameter. The … Aug 11, 2026
CVE-2026-72549 MEDIUM 5.3 An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to map any email address or username to its internal user objectId … Aug 11, 2026
CVE-2026-72548 HIGH 7.5 An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any organisation tenant record via the gettenant Parse cloud function. … Aug 11, 2026
CVE-2026-72547 HIGH 7.1 An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event organiser to bulk import attendees into events belonging to other … Aug 11, 2026
CVE-2026-72546 HIGH 7.1 An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event organiser to inject attendees and orders into events belonging to … Aug 11, 2026
CVE-2026-72545 HIGH 7.5 An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any contact record via the updatecontacttour Parse … Aug 11, 2026
CVE-2026-72544 HIGH 7.5 An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to forge document audit-trail entries via the triggerevent Parse cloud function. The … Aug 11, 2026
CVE-2026-72543 HIGH 7.5 An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any contact record via the getcontact Parse cloud … Aug 11, 2026
CVE-2026-72542 MEDIUM 5.4 A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write job progress and read job metrics for any job in … Aug 11, 2026
CVE-2026-72541 MEDIUM 6.5 A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to overwrite any resource type schema via the update_resource_type endpoint. … Aug 11, 2026
CVE-2026-72540 MEDIUM 4.3 An insecure direct object reference vulnerability in PhotoPrism through commit bb0b933 allows any user with a valid preview token to retrieve the original-resolution cover photo … Aug 11, 2026
CVE-2026-72539 MEDIUM 6.5 An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to read legacy ownerless draft scripts that contain plaintext resource … Aug 11, 2026
CVE-2026-72538 HIGH 8.8 An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code execution via the git_clone pull step branch field. The … Aug 11, 2026
CVE-2026-72537 HIGH 8.8 A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account … Aug 11, 2026
CVE-2026-72536 HIGH 8.6 A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to manipulate any tenant Stripe subscription via the stripeCreateIntent GraphQL mutation. The … Aug 11, 2026
CVE-2026-72535 HIGH 8.6 A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint Stripe Billing Portal sessions for any tenant via the stripeCustomerPortal … Aug 11, 2026
CVE-2026-72534 HIGH 8.8 A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to gain superuser privileges by provisioning … Aug 11, 2026
CVE-2026-72533 HIGH 8.8 An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeating all … Aug 11, 2026
CVE-2026-50237 HIGH 7.4 A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with … Aug 11, 2026
CVE-2026-50236 HIGH 7.4 An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization … Aug 11, 2026
CVE-2026-13739 UNKNOWN A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade … Aug 11, 2026