Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
29528
Total
2302
Critical
8845
High
9186
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-43948 | CRITICAL | 9.9 | wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_edit views in wger perform a gym-scope authorization check using … | May 12, 2026 |
| CVE-2026-42855 | HIGH | 7.5 | arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer Digest authentication implementation in arduino-esp32 … | May 12, 2026 |
| CVE-2026-42854 | CRITICAL | 9.8 | arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer multipart form parser in arduino-esp32 … | May 12, 2026 |
| CVE-2026-42844 | UNKNOWN | — | Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upload to write an arbitrary YAML file … | May 12, 2026 |
| CVE-2026-42545 | MEDIUM | 5.9 | Granian is a Rust HTTP server for Python applications. From 0.2.0 to 2.7.4, Granian aborts a worker process if a WSGI application returns an invalid … | May 12, 2026 |
| CVE-2026-42544 | HIGH | 7.5 | Granian is a Rust HTTP server for Python applications. From 1.2.0 to 2.7.4, Granian aborts a worker process when an unauthenticated client sends a WebSocket … | May 12, 2026 |
| CVE-2026-42268 | UNKNOWN | — | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an … | May 12, 2026 |
| CVE-2026-42196 | UNKNOWN | — | django-s3file is a lightweight file upload input for Django and Amazon S3. Prior to 7.0.2, S3FileMiddleware is vulnerable to relative path traversal attacks, where an … | May 12, 2026 |
| CVE-2026-41195 | MEDIUM | 5.0 | mosparo is the modern solution to protect your online forms from spam. Prior to 1.4.13, the automatic rule package source URL feature allows a project … | May 12, 2026 |
| CVE-2026-40902 | HIGH | 7.5 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the XLSX reader's ColumnAndRowAttributes::readRowAttributes() method … | May 12, 2026 |
| CVE-2026-40863 | HIGH | 7.5 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the SpreadsheetML XML reader (Reader\Xml) … | May 12, 2026 |
| CVE-2026-35555 | MEDIUM | 6.3 | PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an unauthorized deletion of project groups. | May 12, 2026 |
| CVE-2026-33570 | MEDIUM | 5.7 | PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normally limited by operational permissions. | May 12, 2026 |
| CVE-2026-26289 | HIGH | 8.2 | PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions … | May 12, 2026 |
| CVE-2026-44403 | HIGH | 7.2 | Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authenticated administrators to inject arbitrary Lua … | May 12, 2026 |
| CVE-2026-44246 | HIGH | 7.2 | nnU-Net is a semantic segmentation framework that automatically adapts its pipeline to a dataset. Prior to 2.4.1, the nnU-Net Issue Triage workflow in .github/workflows/issue-triage.yml is … | May 12, 2026 |
| CVE-2026-44240 | HIGH | 7.5 | basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when parsing FTP control-channel multiline responses. A … | May 12, 2026 |
| CVE-2026-44232 | UNKNOWN | — | DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.3.0, every IPv6 category bypasses is_url_safe. … | May 12, 2026 |
| CVE-2026-44224 | UNKNOWN | — | Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applies it … | May 12, 2026 |
| CVE-2026-44012 | UNKNOWN | — | Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::actionShowInFolder() fetches an asset by ID and returns its filename and complete … | May 12, 2026 |
| CVE-2026-44011 | UNKNOWN | — | Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, Craft CMS which contains an input-handling flaw in a Yii … | May 12, 2026 |
| CVE-2026-44010 | UNKNOWN | — | Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, the GraphQL Address element resolver (src/gql/resolvers/elements/Address.php) performs no schema scope … | May 12, 2026 |
| CVE-2026-35504 | MEDIUM | 5.5 | PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communication. | May 12, 2026 |
| CVE-2025-65088 | UNKNOWN | — | An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to … | May 12, 2026 |
| CVE-2025-65087 | UNKNOWN | — | An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to … | May 12, 2026 |