Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48891
Total
3931
Critical
14494
High
14248
Medium
CVE ID Severity Score Description Published
CVE-2026-73156 UNKNOWN Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap tooltip formatters. Slice names may originate directly from STIX or … Aug 11, 2026
CVE-2026-73155 UNKNOWN Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first checking whether those users are authorized to view … Aug 11, 2026
CVE-2026-73140 UNKNOWN Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report exports. Although normal comment retrieval filters comments according to conversion visibility, … Aug 11, 2026
CVE-2026-19519 MEDIUM 4.3 A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked type assertion to panic … Aug 11, 2026
CVE-2026-19418 UNKNOWN The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the … Aug 11, 2026
CVE-2026-19518 MEDIUM 6.5 Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation. Aug 11, 2026
CVE-2026-19517 MEDIUM 6.5 Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlottie allows Excessive Allocation. Aug 11, 2026
CVE-2026-19391 MEDIUM 6.5 A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD … Aug 11, 2026
CVE-2026-16053 HIGH 8.5 Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module. Aug 11, 2026
CVE-2026-8158 MEDIUM 5.3 The Signed Video Framework contained a buffer overflow issue which could lead the application using this framework to crash. The issue exclusively affects the tools … Aug 11, 2026
CVE-2026-6505 MEDIUM 5.1 The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if … Aug 11, 2026
CVE-2026-6181 MEDIUM 5.9 The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer-privileged service account. Aug 11, 2026
CVE-2026-5304 MEDIUM 5.7 An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is … Aug 11, 2026
CVE-2026-5303 MEDIUM 5.7 The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if … Aug 11, 2026
CVE-2026-4757 HIGH 7.2 A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can only be … Aug 11, 2026
CVE-2026-19516 CRITICAL 9.1 A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, … Aug 11, 2026
CVE-2026-18348 MEDIUM 4.1 Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor … Aug 11, 2026
CVE-2026-14549 UNKNOWN The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated … Aug 11, 2026
CVE-2026-14548 UNKNOWN The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated … Aug 11, 2026
CVE-2026-13716 CRITICAL 9.1 Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to … Aug 11, 2026
CVE-2026-12052 MEDIUM 5.2 The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next/class/usbd_cdc_ncm.c builds a fixed-size response for the GET_NTB_PARAMETERS (28-byte struct ntb_parameters) and GET_NTB_INPUT_SIZE (8-byte struct … Aug 11, 2026
CVE-2026-12051 MEDIUM 4.6 The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer dereference in handle_download() (subsys/usb/device_next/class/usbd_dfu.c). The handler computes MIN(setup->wLength, … Aug 11, 2026
CVE-2026-11894 MEDIUM 5.9 The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the bt_hci_driver_api buffer-ownership contract. That contract requires the driver to consume (unref) the … Aug 11, 2026
CVE-2026-19425 CRITICAL 9.8 Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, … Aug 11, 2026
CVE-2026-16974 MEDIUM 6.4 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post_meta Shortcode in all … Aug 11, 2026