Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49645
Total
4014
Critical
14740
High
14481
Medium
CVE ID Severity Score Description Published
CVE-2026-18927 MEDIUM 6.3 A vulnerability was determined in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c. This affects the function storeProfileImage of the file student_profile_pic.php of the component Shared Upload Helper. Executing a … Aug 05, 2026
CVE-2026-17630 HIGH 7.2 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of configuration parameters. Aug 05, 2026
CVE-2026-17626 HIGH 8.8 IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due … Aug 05, 2026
CVE-2026-17623 HIGH 8.8 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the command field in … Aug 05, 2026
CVE-2026-17617 HIGH 8.5 IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources. Aug 05, 2026
CVE-2026-14587 UNKNOWN Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends … Aug 05, 2026
CVE-2026-9203 HIGH 8.5 A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud … Aug 05, 2026
CVE-2026-9195 CRITICAL 9.3 A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator … Aug 05, 2026
CVE-2026-9193 CRITICAL 9.9 An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop … Aug 05, 2026
CVE-2026-9192 CRITICAL 9.8 An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password … Aug 05, 2026
CVE-2026-9190 CRITICAL 9.1 An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication … Aug 05, 2026
CVE-2026-8709 CRITICAL 9.9 An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with … Aug 05, 2026
CVE-2026-8400 HIGH 8.1 IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM … Aug 05, 2026
CVE-2026-7557 CRITICAL 9.1 An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker … Aug 05, 2026
CVE-2026-7329 CRITICAL 9.9 An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated … Aug 05, 2026
CVE-2026-7327 HIGH 8.1 An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with … Aug 05, 2026
CVE-2026-7326 HIGH 7.5 A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated … Aug 05, 2026
CVE-2026-70606 MEDIUM 5.9 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6, 41.9.1, 42.5.1, and 43.0.0, when a custom protocol … Aug 05, 2026
CVE-2026-70605 MEDIUM 5.9 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, when following HTTP redirects, … Aug 05, 2026
CVE-2026-70604 HIGH 7.4 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0, a custom scheme registered … Aug 05, 2026
CVE-2026-70603 MEDIUM 6.0 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1, shell.openPath() did not reject … Aug 05, 2026
CVE-2026-70602 MEDIUM 6.6 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, extension tab and scripting … Aug 05, 2026
CVE-2026-70601 HIGH 7.5 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps that expose Promise-returning … Aug 05, 2026
CVE-2026-70600 LOW 3.1 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autofill popup … Aug 05, 2026
CVE-2026-70599 MEDIUM 5.9 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, serial-port and media permission … Aug 05, 2026