Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49177
Total
3940
Critical
14579
High
14345
Medium
CVE ID Severity Score Description Published
CVE-2026-15972 HIGH 7.5 Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC … Aug 07, 2026
CVE-2026-15970 MEDIUM 4.2 Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a … Aug 07, 2026
CVE-2026-71852 UNKNOWN pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py … Aug 07, 2026
CVE-2026-71851 CRITICAL 9.0 crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry … Aug 07, 2026
CVE-2026-71850 MEDIUM 4.8 Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from hono/jsx retains the result of a … Aug 07, 2026
CVE-2026-71849 LOW 3.7 Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy Helper proxy() function in hono/proxy does … Aug 07, 2026
CVE-2026-71848 MEDIUM 5.3 Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the languageDetector middleware is vulnerable to algorithmic complexity … Aug 07, 2026
CVE-2026-71847 UNKNOWN Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves … Aug 07, 2026
CVE-2026-70561 MEDIUM 6.5 TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege guest accounts, to read arbitrary attachments by … Aug 07, 2026
CVE-2026-69127 UNKNOWN Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error … Aug 07, 2026
CVE-2026-66000 UNKNOWN Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing … Aug 07, 2026
CVE-2026-48098 HIGH 7.3 NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 execute privileged … Aug 07, 2026
CVE-2026-48097 HIGH 7.8 NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a … Aug 07, 2026
CVE-2026-19231 HIGH 7.3 A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=delete_appointment. The manipulation of … Aug 07, 2026
CVE-2026-19230 LOW 3.5 A vulnerability was identified in SourceCodester Photo Share Website 1.0. This affects an unknown part of the file /social/ajax.php?action=save_upload of the component Comment Input Box. … Aug 07, 2026
CVE-2026-17435 UNKNOWN File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files. When the file to be rotated is a symbolic link … Aug 07, 2026
CVE-2026-11430 HIGH 7.3 Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook feature is enabled but no webhookToken is configured, a … Aug 07, 2026
CVE-2025-71413 MEDIUM 5.3 Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets which may result in increased workload and reduced … Aug 07, 2026
CVE-2025-71412 HIGH 7.1 Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper response actions by flight crews, traffic … Aug 07, 2026
CVE-2025-71411 MEDIUM 5.3 Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out … Aug 07, 2026
CVE-2025-71410 MEDIUM 5.3 Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and lead to a loss of CPDLC functions requiring … Aug 07, 2026
CVE-2025-71409 HIGH 7.1 Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and … Aug 07, 2026
CVE-2025-63235 HIGH 7.5 In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients send invalid CONNECT packets … Aug 07, 2026
CVE-2026-66058 UNKNOWN Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is possible for an authenticated … Aug 07, 2026
CVE-2026-64638 UNKNOWN WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it … Aug 07, 2026