Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49853
Total
4028
Critical
14819
High
14575
Medium
CVE ID Severity Score Description Published
CVE-2026-18895 HIGH 8.8 A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the … Aug 05, 2026
CVE-2026-18859 HIGH 7.3 A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/ukey/usbkey;logindojojs. Such manipulation of the argument keyid … Aug 05, 2026
CVE-2026-18856 MEDIUM 4.7 A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFile of the file modules/importer/importer.admin.controller.php of the component Data Import … Aug 05, 2026
CVE-2026-46334 UNKNOWN OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the SDP bandwidth-line … Aug 05, 2026
CVE-2026-45809 UNKNOWN OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the watcherinfo generation … Aug 05, 2026
CVE-2026-45705 MEDIUM 5.3 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the find_line_delimiter() function in the multipart body parser performs … Aug 05, 2026
CVE-2026-18854 HIGH 7.3 A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClassByFilter of the … Aug 05, 2026
CVE-2026-18853 MEDIUM 5.3 A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the function t5.l.c of the component com.zombodroid.MemeGenerator. Such … Aug 05, 2026
CVE-2026-18852 LOW 3.3 A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This impacts the function SplitTokens/ShuntingYard of the file engine/query/expr/expr.cpp of the component Filter Parser. … Aug 05, 2026
CVE-2026-18103 MEDIUM 4.9 A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Programming Interface) port, especially if not secured … Aug 05, 2026
CVE-2026-45537 CRITICAL 9.1 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI components (protocol, username, … Aug 04, 2026
CVE-2026-18819 MEDIUM 4.3 A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack … Aug 04, 2026
CVE-2026-18818 MEDIUM 6.3 A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView of the file apps/sspanel/views.py of the component Support Ticket … Aug 04, 2026
CVE-2026-70620 MEDIUM 6.8 Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to probe internal network resources by supplying … Aug 04, 2026
CVE-2026-70619 HIGH 8.8 Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes … Aug 04, 2026
CVE-2026-70594 MEDIUM 6.7 Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for … Aug 04, 2026
CVE-2026-70593 MEDIUM 6.6 Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of … Aug 04, 2026
CVE-2026-70592 MEDIUM 5.5 Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database … Aug 04, 2026
CVE-2026-70591 MEDIUM 4.1 Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to … Aug 04, 2026
CVE-2026-70590 MEDIUM 4.8 Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through … Aug 04, 2026
CVE-2026-70589 MEDIUM 4.8 Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer … Aug 04, 2026
CVE-2026-67862 UNKNOWN open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. This allows a remote attacker to cause a denial of service. Aug 04, 2026
CVE-2026-67861 HIGH 7.5 An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component Aug 04, 2026
CVE-2026-67860 UNKNOWN open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend. Aug 04, 2026
CVE-2026-67859 HIGH 7.5 Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling. Aug 04, 2026