Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49608
Total
4010
Critical
14727
High
14463
Medium
CVE ID Severity Score Description Published
CVE-2026-64993 MEDIUM 6.8 Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading … Aug 06, 2026
CVE-2026-5134 CRITICAL 9.8 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection. This … Aug 06, 2026
CVE-2026-19041 MEDIUM 6.3 A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageService.installPackage of the file src/controllers/packages.ts of the component … Aug 06, 2026
CVE-2026-19040 MEDIUM 6.3 A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/services/dcrClients.ts. Executing a manipulation … Aug 06, 2026
CVE-2026-18501 MEDIUM 6.4 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting … Aug 06, 2026
CVE-2026-16731 UNKNOWN OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid … Aug 06, 2026
CVE-2026-16316 MEDIUM 4.3 OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame processing. A specially crafted SV frame can cause … Aug 06, 2026
CVE-2026-16315 HIGH 8.7 OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid … Aug 06, 2026
CVE-2026-12605 CRITICAL 9.6 In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated … Aug 06, 2026
CVE-2026-70556 MEDIUM 4.3 Hubzilla 11.2.1 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint handled by Zotlabs\Module\Authorize::post() that allows unauthenticated attackers to register arbitrary OAuth2 applications … Aug 06, 2026
CVE-2026-66733 HIGH 7.5 Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enqueuePacket() that allows unauthenticated remote attackers to crash the server process by … Aug 06, 2026
CVE-2026-66732 MEDIUM 5.9 Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager where established connections are resolved by a two-byte local connection … Aug 06, 2026
CVE-2026-65551 HIGH 7.5 Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Breakdance: from n/a before 2.7. Aug 06, 2026
CVE-2026-19039 MEDIUM 5.3 A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted is the function ssh_exec of the file src/index.ts of the component SSH Command Handler. … Aug 06, 2026
CVE-2026-19038 MEDIUM 6.3 A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function screenshotElement of the file src/index.ts of the component screenshot_element Tool. … Aug 06, 2026
CVE-2026-19037 MEDIUM 4.3 A weakness has been identified in WonderTrader up to 0.9.9. This vulnerability affects the function MatchEngine::update_lob of the file src/WtBtCore/MatchEngine.cpp of the component Internal Limit … Aug 06, 2026
CVE-2026-19036 HIGH 7.2 A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom … Aug 06, 2026
CVE-2026-15599 LOW 3.3 Unverified ownership vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-domain-joiner allows Privilege Abuse. This issue affects pardus-domain-joiner: before 0.5.5. Aug 06, 2026
CVE-2026-0673 MEDIUM 5.3 The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via the … Aug 06, 2026
CVE-2026-8166 MEDIUM 5.4 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Industry and Trade Inc. E-Logo Purchasing Portal allows Stored XSS. This … Aug 06, 2026
CVE-2026-68481 HIGH 7.5 In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations … Aug 06, 2026
CVE-2026-68079 CRITICAL 9.8 In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the … Aug 06, 2026
CVE-2026-65583 CRITICAL 9.1 Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted … Aug 06, 2026
CVE-2026-63687 CRITICAL 9.1 Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce … Aug 06, 2026
CVE-2026-61466 CRITICAL 9.1 In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without … Aug 06, 2026