Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49853
Total
4028
Critical
14819
High
14575
Medium
CVE ID Severity Score Description Published
CVE-2026-12698 MEDIUM 4.3 The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with … Aug 04, 2026
CVE-2026-11366 LOW 3.7 The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPress plugin before … Aug 04, 2026
CVE-2026-10526 MEDIUM 5.8 The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site … Aug 04, 2026
CVE-2026-68744 LOW 3.3 A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the … Aug 04, 2026
CVE-2026-18739 LOW 2.5 A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application … Aug 04, 2026
CVE-2026-18569 LOW 3.7 A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component … Aug 04, 2026
CVE-2026-16881 UNKNOWN A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component does not adequately validate or sandbox externally … Aug 04, 2026
CVE-2026-42169 HIGH 7.3 A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading … Aug 04, 2026
CVE-2026-18723 MEDIUM 6.3 A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file /api/dwsurvey/app/survey/up-survey-status.do of the component Survey … Aug 04, 2026
CVE-2026-18722 MEDIUM 6.3 A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do of the component Survey Handler. … Aug 04, 2026
CVE-2026-18721 MEDIUM 4.3 A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown processing of the file /user/sso/apiLogin of the component SSO … Aug 04, 2026
CVE-2026-14818 HIGH 7.2 A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, … Aug 04, 2026
CVE-2026-8508 MEDIUM 6.5 An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass … Aug 04, 2026
CVE-2026-6837 HIGH 7.2 A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges … Aug 04, 2026
CVE-2026-18720 MEDIUM 5.3 A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?plugin/msgWarning/action of the component msgWarning Plugin. … Aug 04, 2026
CVE-2026-17614 MEDIUM 4.4 A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getConfigurationFile() methods in wildfly-core/deployment-repository do not validate that the resolved file … Aug 04, 2026
CVE-2026-18719 MEDIUM 6.3 A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the component Search. Performing a manipulation of … Aug 04, 2026
CVE-2026-58045 MEDIUM 6.2 A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. … Aug 04, 2026
CVE-2026-58044 LOW 3.7 A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while … Aug 04, 2026
CVE-2026-58042 MEDIUM 5.9 A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records. Repeated triggering of this … Aug 04, 2026
CVE-2026-58041 MEDIUM 5.3 A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it has been reset and … Aug 04, 2026
CVE-2026-56846 HIGH 7.5 A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and … Aug 04, 2026
CVE-2026-56845 HIGH 7.5 An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an … Aug 04, 2026
CVE-2026-66326 MEDIUM 6.5 Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Aug 04, 2026
CVE-2026-66325 MEDIUM 6.1 Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. Aug 04, 2026