Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

28561
Total
2193
Critical
8548
High
8866
Medium
CVE ID Severity Score Description Published
CVE-2026-5947 HIGH 7.5 Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it … May 20, 2026
CVE-2026-5946 HIGH 7.5 Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or … May 20, 2026
CVE-2026-45584 HIGH 8.1 Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. May 20, 2026
CVE-2026-45498 MEDIUM 4.0 Microsoft Defender Denial of Service Vulnerability May 20, 2026
CVE-2026-45443 MEDIUM 5.0 Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Exploiting Incorrectly Configured Access Control Security Levels. This issue … May 20, 2026
CVE-2026-42834 HIGH 7.8 Improper link resolution before file access ('link following') in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally. May 20, 2026
CVE-2026-42383 HIGH 7.6 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Blind SQL Injection. This issue … May 20, 2026
CVE-2026-41091 HIGH 7.8 Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. May 20, 2026
CVE-2026-3593 HIGH 7.4 A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1. BIND … May 20, 2026
CVE-2026-3592 MEDIUM 5.3 BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will … May 20, 2026
CVE-2026-3039 HIGH 7.5 BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically … May 20, 2026
CVE-2026-29518 HIGH 7.0 Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended … May 20, 2026
CVE-2026-27424 MEDIUM 4.3 Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Image Photo … May 20, 2026
CVE-2026-27405 MEDIUM 6.5 Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9. May 20, 2026
CVE-2026-24573 MEDIUM 6.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Stored XSS. This issue affects Visualizer: from n/a before 4.0.0. May 20, 2026
CVE-2025-11954 HIGH 8.0 Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross Site Request Forgery. This issue affects WISECP: through 20022026. NOTE: … May 20, 2026
CVE-2025-31985 LOW 3.7 HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform … May 20, 2026
CVE-2025-31973 MEDIUM 4.0 HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce … May 20, 2026
CVE-2026-25602 MEDIUM 4.4 Insufficient Verification of Data Authenticity vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component makes it possible to send messages to any email … May 20, 2026
CVE-2026-22315 HIGH 7.2 Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables the export of user data, including cleartext passwords, via the … May 20, 2026
CVE-2026-22314 CRITICAL 9.0 Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' … May 20, 2026
CVE-2026-0857 MEDIUM 6.0 Cleartext Storage of Sensitive Information in Memory vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component. This issue affects Meona Client Launcher Component: … May 20, 2026
CVE-2026-0856 HIGH 7.8 Improper Access Control vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables a normal user gaining access to the admin panel. This … May 20, 2026
CVE-2026-9064 HIGH 7.5 A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per … May 20, 2026
CVE-2026-6728 MEDIUM 5.3 The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.9 via the 'get_stream_data()' function. This makes … May 20, 2026