Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48919
Total
3931
Critical
14503
High
14257
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-30237 | UNKNOWN | — | The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certain endpoints. An attacker … | Aug 10, 2026 |
| CVE-2026-72919 | MEDIUM | 4.3 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the channels.convertToTeam REST endpoint allows … | Aug 10, 2026 |
| CVE-2026-72918 | MEDIUM | 5.4 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the stream-notify-user stream in the … | Aug 10, 2026 |
| CVE-2026-72917 | MEDIUM | 5.9 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, AnythingLLM's … | Aug 10, 2026 |
| CVE-2026-72916 | UNKNOWN | — | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, PrivateAddressCheck.private_address? in app/lib/private_address_check.rb normalized IPv4-mapped IPv6 addresses … | Aug 10, 2026 |
| CVE-2026-72915 | HIGH | 7.5 | Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user could use the show … | Aug 10, 2026 |
| CVE-2026-72914 | HIGH | 7.5 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-beta.1, the administrative statistics endpoints handled by Api::V1::Admin::MeasuresController … | Aug 10, 2026 |
| CVE-2026-6426 | MEDIUM | 4.4 | A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size is stored as a uint64_t but read by … | Aug 10, 2026 |
| CVE-2025-32736 | UNKNOWN | — | Cross-Site Request Forgery weaknesses in the Administrative Console of PingFederate versions before version 13.1 may allow actors to perform unauthorized actions via specially-crafted links triggered … | Aug 10, 2026 |
| CVE-2026-73035 | MEDIUM | 4.3 | npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability that allows an attacker to embed arbitrary terminal control characters in … | Aug 10, 2026 |
| CVE-2026-73033 | MEDIUM | 6.5 | Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmission() method in src/integrity.lib.php that allows authenticated administrators to delete arbitrary … | Aug 10, 2026 |
| CVE-2026-73030 | HIGH | 8.1 | unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ … | Aug 10, 2026 |
| CVE-2026-72913 | UNKNOWN | — | Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's … | Aug 10, 2026 |
| CVE-2026-72912 | MEDIUM | 4.3 | CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-recipe parser in src/core/Utils.mjs can exhaust client-side CPU when … | Aug 10, 2026 |
| CVE-2026-72911 | CRITICAL | 9.9 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_template and render_template calls in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py render subject, … | Aug 10, 2026 |
| CVE-2026-72910 | HIGH | 7.1 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, pause_job_for_doc, trigger_job_for_doc, change_release_date, and update_cost_center functions across … | Aug 10, 2026 |
| CVE-2026-72909 | UNKNOWN | — | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions path in erpnext/accounts/report/accounts_receivable/accounts_receivable.py does not apply … | Aug 10, 2026 |
| CVE-2026-72908 | MEDIUM | 6.5 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts/doctype/tax_rule/tax_rule.py constructs an SQL WHERE … | Aug 10, 2026 |
| CVE-2026-72907 | MEDIUM | 6.5 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function in erpnext/accounts/utils.py accepts the ignore_permissions argument … | Aug 10, 2026 |
| CVE-2026-72906 | MEDIUM | 4.3 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email function in erpnext/accounts/doctype/process_statement_of_accounts/process_statement_of_accounts.py lacks a Process Statement … | Aug 10, 2026 |
| CVE-2026-72905 | UNKNOWN | — | Rejected reason: Further research determined the issue is not a vulnerability. | Aug 10, 2026 |
| CVE-2026-72904 | UNKNOWN | — | Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in Firecrawl's extraction functionality due … | Aug 10, 2026 |
| CVE-2026-72903 | HIGH | 8.1 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In … | Aug 10, 2026 |
| CVE-2026-72743 | MEDIUM | 5.4 | SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders TinyMCE output via v-html without … | Aug 10, 2026 |
| CVE-2026-63622 | HIGH | 7.8 | A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the … | Aug 10, 2026 |