Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49232
Total
3944
Critical
14598
High
14363
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-19207 | LOW | 2.4 | A security vulnerability has been detected in PHPGurukul Company Visitor Management System 1.0. This issue affects some unknown processing of the file /manage-newvisitors.php. The manipulation … | Aug 07, 2026 |
| CVE-2026-18497 | UNKNOWN | — | A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. The vulnerability exists … | Aug 07, 2026 |
| CVE-2022-4995 | CRITICAL | 9.8 | Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP … | Aug 07, 2026 |
| CVE-2026-66914 | UNKNOWN | — | Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download files from both … | Aug 07, 2026 |
| CVE-2026-61477 | LOW | 2.3 | An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes … | Aug 07, 2026 |
| CVE-2026-37171 | MEDIUM | 5.9 | A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, data, and … | Aug 07, 2026 |
| CVE-2026-19206 | MEDIUM | 5.3 | A security flaw has been discovered in MZ Automation libiec61850 up to 1.6.1. This affects the function SVReceiver_stopThreadless of the file src/sampled_values/sv_subscriber.c of the component … | Aug 07, 2026 |
| CVE-2026-16637 | UNKNOWN | — | OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints. | Aug 07, 2026 |
| CVE-2026-15570 | UNKNOWN | — | An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE24553B45V2DZ Smart TV running on the Vestel MB181 / … | Aug 07, 2026 |
| CVE-2026-66838 | UNKNOWN | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex allows SQL Injection via the :comment option of Postgrex.stream/4. … | Aug 07, 2026 |
| CVE-2026-66494 | UNKNOWN | — | Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript … | Aug 07, 2026 |
| CVE-2026-56794 | MEDIUM | 6.5 | Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this … | Aug 07, 2026 |
| CVE-2026-56793 | HIGH | 7.7 | Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading … | Aug 07, 2026 |
| CVE-2026-48094 | UNKNOWN | — | The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulnerability caused by the absence of WordPress's `esc_url()` escaping function on the `$url` … | Aug 07, 2026 |
| CVE-2026-15816 | HIGH | 7.5 | A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting … | Aug 07, 2026 |
| CVE-2026-71560 | CRITICAL | 9.1 | Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer … | Aug 07, 2026 |
| CVE-2026-71559 | HIGH | 7.5 | Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data … | Aug 07, 2026 |
| CVE-2026-71558 | CRITICAL | 9.8 | Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can … | Aug 07, 2026 |
| CVE-2026-54218 | UNKNOWN | — | Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally in David, passwords are stored in various files using … | Aug 07, 2026 |
| CVE-2026-54217 | UNKNOWN | — | Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send an email containing malicious JavaScript code. When a … | Aug 07, 2026 |
| CVE-2026-54216 | UNKNOWN | — | Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By sending a specially crafted link including an arbitrary path, an XSS … | Aug 07, 2026 |
| CVE-2026-54215 | UNKNOWN | — | Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnerability to craft a URL within … | Aug 07, 2026 |
| CVE-2026-54214 | UNKNOWN | — | Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL parameter, which allows arbitrary modification of the Content-Type header … | Aug 07, 2026 |
| CVE-2026-54213 | UNKNOWN | — | Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. This … | Aug 07, 2026 |
| CVE-2026-54212 | UNKNOWN | — | Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow condition. By submitting a specially crafted JSON body, … | Aug 07, 2026 |