Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
29082
Total
2258
Critical
8681
High
9062
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-38719 | MEDIUM | 6.2 | OpENer v2.3-558-g1e99582 contains an out-of-bounds read vulnerability in the Common Packet Format (CPF) parser, specifically in CreateCommonPacketFormatStructure() in source/src/enet_encap/cpf.c. A crafted ENIP/CPF message can supply … | May 18, 2026 |
| CVE-2026-36438 | MEDIUM | 5.3 | An issue in Intelbras VIP-1230-D-G4 Version V2.800.00IB00C.0.T allows a remote attacker to obtain sensitive information via password reset functionality under /OutsideCmd | May 18, 2026 |
| CVE-2026-20685 | MEDIUM | 6.5 | An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation. This issue … | May 18, 2026 |
| CVE-2025-57282 | HIGH | 8.8 | ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection. | May 18, 2026 |
| CVE-2025-56352 | HIGH | 7.5 | In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations during CONNECT packet parsing. When receiving a CONNECT packet with a zero-length Client ID while … | May 18, 2026 |
| CVE-2026-41949 | MEDIUM | 5.9 | Dify version 1.14.1 and prior contain an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 … | May 18, 2026 |
| CVE-2026-41948 | HIGH | 7.7 | Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API … | May 18, 2026 |
| CVE-2026-41947 | HIGH | 7.4 | Dify version 1.14.1 and prior contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless … | May 18, 2026 |
| CVE-2026-39079 | HIGH | 7.5 | An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive information via the /modules/upsshipping/logs/, and /modules/upsshipping/lib/UPSBaseApi.php components | May 18, 2026 |
| CVE-2026-26462 | UNKNOWN | — | Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration. The application enables Node.js integration while disabling context isolation, … | May 18, 2026 |
| CVE-2026-42009 | HIGH | 7.5 | A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator … | May 18, 2026 |
| CVE-2026-8803 | LOW | 3.7 | A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of … | May 18, 2026 |
| CVE-2026-7304 | CRITICAL | 9.8 | SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will be … | May 18, 2026 |
| CVE-2026-7302 | CRITICAL | 9.1 | SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write … | May 18, 2026 |
| CVE-2026-7301 | CRITICAL | 9.8 | SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when … | May 18, 2026 |
| CVE-2026-0983 | UNKNOWN | — | Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user to cause the MFserver process … | May 18, 2026 |
| CVE-2026-8802 | MEDIUM | 4.3 | A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The … | May 18, 2026 |
| CVE-2026-4320 | UNKNOWN | — | Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to protected features by manipulating the HTTP redirect headers of … | May 18, 2026 |
| CVE-2026-41119 | MEDIUM | 6.8 | Dell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to … | May 18, 2026 |
| CVE-2026-7498 | HIGH | 8.8 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Information Technology Consulting and Organization Trade Ltd. Co. DernekWeb allows Stored XSS. … | May 18, 2026 |
| CVE-2026-6902 | UNKNOWN | — | A vulnerability in Command-Line Client in P4 Server prior to the 2025.2 Patch 2, identified as CVE-2026-6902, has been fixed in P4 Server to address … | May 18, 2026 |
| CVE-2026-6347 | HIGH | 7.6 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields in the Mattermost Calls plugin which allows an … | May 18, 2026 |
| CVE-2026-6346 | HIGH | 8.7 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields before including them in support packet generation, which … | May 18, 2026 |
| CVE-2026-6345 | MEDIUM | 6.5 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure of created user password which allows a malicious attacker to impersonate … | May 18, 2026 |
| CVE-2026-6343 | MEDIUM | 4.3 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check public/private permissions which allows members without these permissions to access public … | May 18, 2026 |