Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49608
Total
4010
Critical
14727
High
14463
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-64993 | MEDIUM | 6.8 | Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading … | Aug 06, 2026 |
| CVE-2026-5134 | CRITICAL | 9.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection. This … | Aug 06, 2026 |
| CVE-2026-19041 | MEDIUM | 6.3 | A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageService.installPackage of the file src/controllers/packages.ts of the component … | Aug 06, 2026 |
| CVE-2026-19040 | MEDIUM | 6.3 | A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/services/dcrClients.ts. Executing a manipulation … | Aug 06, 2026 |
| CVE-2026-18501 | MEDIUM | 6.4 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting … | Aug 06, 2026 |
| CVE-2026-16731 | UNKNOWN | — | OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid … | Aug 06, 2026 |
| CVE-2026-16316 | MEDIUM | 4.3 | OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame processing. A specially crafted SV frame can cause … | Aug 06, 2026 |
| CVE-2026-16315 | HIGH | 8.7 | OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid … | Aug 06, 2026 |
| CVE-2026-12605 | CRITICAL | 9.6 | In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated … | Aug 06, 2026 |
| CVE-2026-70556 | MEDIUM | 4.3 | Hubzilla 11.2.1 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint handled by Zotlabs\Module\Authorize::post() that allows unauthenticated attackers to register arbitrary OAuth2 applications … | Aug 06, 2026 |
| CVE-2026-66733 | HIGH | 7.5 | Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enqueuePacket() that allows unauthenticated remote attackers to crash the server process by … | Aug 06, 2026 |
| CVE-2026-66732 | MEDIUM | 5.9 | Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager where established connections are resolved by a two-byte local connection … | Aug 06, 2026 |
| CVE-2026-65551 | HIGH | 7.5 | Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Breakdance: from n/a before 2.7. | Aug 06, 2026 |
| CVE-2026-19039 | MEDIUM | 5.3 | A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted is the function ssh_exec of the file src/index.ts of the component SSH Command Handler. … | Aug 06, 2026 |
| CVE-2026-19038 | MEDIUM | 6.3 | A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function screenshotElement of the file src/index.ts of the component screenshot_element Tool. … | Aug 06, 2026 |
| CVE-2026-19037 | MEDIUM | 4.3 | A weakness has been identified in WonderTrader up to 0.9.9. This vulnerability affects the function MatchEngine::update_lob of the file src/WtBtCore/MatchEngine.cpp of the component Internal Limit … | Aug 06, 2026 |
| CVE-2026-19036 | HIGH | 7.2 | A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom … | Aug 06, 2026 |
| CVE-2026-15599 | LOW | 3.3 | Unverified ownership vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-domain-joiner allows Privilege Abuse. This issue affects pardus-domain-joiner: before 0.5.5. | Aug 06, 2026 |
| CVE-2026-0673 | MEDIUM | 5.3 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via the … | Aug 06, 2026 |
| CVE-2026-8166 | MEDIUM | 5.4 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Industry and Trade Inc. E-Logo Purchasing Portal allows Stored XSS. This … | Aug 06, 2026 |
| CVE-2026-68481 | HIGH | 7.5 | In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations … | Aug 06, 2026 |
| CVE-2026-68079 | CRITICAL | 9.8 | In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the … | Aug 06, 2026 |
| CVE-2026-65583 | CRITICAL | 9.1 | Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted … | Aug 06, 2026 |
| CVE-2026-63687 | CRITICAL | 9.1 | Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce … | Aug 06, 2026 |
| CVE-2026-61466 | CRITICAL | 9.1 | In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without … | Aug 06, 2026 |