Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48919
Total
3931
Critical
14503
High
14257
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-72724 | MEDIUM | 4.3 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, plugins/chat/lib/chat/onebox_handler.rb resolves Chat::Thread by route thread_id independently of the route channel_id before … | Aug 10, 2026 |
| CVE-2026-72723 | MEDIUM | 5.3 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.anonymous_default_navigation_menu_tags serializes tags from SiteSetting.default_navigation_menu_tags without applying DiscourseTagging.filter_visible for the anonymous viewer. … | Aug 10, 2026 |
| CVE-2026-72722 | MEDIUM | 4.3 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, TopicLink.extract_from, TopicLink.ensure_entry_for, and TopicLink.duplicate_lookup do not consistently enforce Guardian.can_see? checks when processing … | Aug 10, 2026 |
| CVE-2026-72721 | MEDIUM | 5.3 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Onebox::DomainChecker.is_blocked? compares hostnames and SiteSetting.blocked_onebox_domains entries case-sensitively, allowing an attacker to bypass … | Aug 10, 2026 |
| CVE-2026-72720 | MEDIUM | 6.4 | Discourse is an open-source discussion platform. Prior to 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, Discourse has HTML injection in PrettyText.format_for_email because cooked attribute values are reparsed … | Aug 10, 2026 |
| CVE-2026-72719 | MEDIUM | 6.7 | Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transfer Portals, Automation Rules, Macros, and Twilio Channels to other … | Aug 10, 2026 |
| CVE-2026-72718 | UNKNOWN | — | goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system `git` executable to gather the … | Aug 10, 2026 |
| CVE-2026-66738 | HIGH | 8.8 | SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization and … | Aug 10, 2026 |
| CVE-2026-56620 | MEDIUM | 4.3 | HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error reporting. | Aug 10, 2026 |
| CVE-2026-48158 | UNKNOWN | — | use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34, the default branch contained malicious commits 9d8481a513b7b0d1c0941b220c69b25de748641b through 6f2dae054ca014068bdbbb4db96006424d674124 that executed … | Aug 10, 2026 |
| CVE-2026-48048 | HIGH | 7.5 | XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, … | Aug 10, 2026 |
| CVE-2026-47754 | CRITICAL | 9.3 | Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions contain an unauthenticated path … | Aug 10, 2026 |
| CVE-2026-72761 | UNKNOWN | — | The webhook URL validator in `website/notifications/webhooks.py` uses `ip.is_global` to reject non-public addresses after DNS resolution. IPv6 transition addresses (NAT64 `64:ff9b::/96`, 6to4 `2002::/16`, Teredo `2001:0000::/32`) are … | Aug 10, 2026 |
| CVE-2026-72760 | UNKNOWN | — | Affected versions of MISP cti-transmute disclose users' email addresses through the account following-list endpoint. When an authenticated user follows another account, get_following() includes the followed … | Aug 10, 2026 |
| CVE-2026-72759 | UNKNOWN | — | In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization check. When a history record references a deleted conversion, the associated … | Aug 10, 2026 |
| CVE-2026-19433 | UNKNOWN | — | Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before 5.4.8 allows authenticated users of any company to blindly … | Aug 10, 2026 |
| CVE-2026-18412 | UNKNOWN | — | OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 extension installer extracts these zip files, but does not validate … | Aug 10, 2026 |
| CVE-2026-72751 | UNKNOWN | — | CTI-Transmute is affected by a stored cross-site scripting (XSS) vulnerability in the conversion graph used to visualise converted MISP and STIX content. Attacker-controlled values originating … | Aug 10, 2026 |
| CVE-2026-71959 | MEDIUM | 5.8 | Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /collect request body, allowing any … | Aug 10, 2026 |
| CVE-2026-63106 | CRITICAL | 9.8 | ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly … | Aug 10, 2026 |
| CVE-2026-63105 | MEDIUM | 5.4 | ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated customers to inject malicious HTML payloads through the chat and support ticket … | Aug 10, 2026 |
| CVE-2026-59112 | UNKNOWN | — | Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc on Android, … | Aug 10, 2026 |
| CVE-2026-18503 | UNKNOWN | — | Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv.Sniffer.sniff(). | Aug 10, 2026 |
| CVE-2026-18478 | UNKNOWN | — | Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of … | Aug 10, 2026 |
| CVE-2026-16742 | MEDIUM | 6.7 | systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user | Aug 10, 2026 |