Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50089
Total
4047
Critical
14897
High
14637
Medium
CVE ID Severity Score Description Published
CVE-2026-14219 MEDIUM 5.4 URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Phishing. This issue affects HUMANIST … Aug 04, 2026
CVE-2026-14202 MEDIUM 5.3 Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting. This issue affects HUMANIST Digital Human Resources: … Aug 04, 2026
CVE-2026-14194 MEDIUM 6.5 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Path … Aug 04, 2026
CVE-2026-14192 MEDIUM 5.4 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Stored XSS. … Aug 04, 2026
CVE-2026-14175 CRITICAL 9.8 Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to … Aug 04, 2026
CVE-2026-67243 HIGH 7.2 freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may … Aug 04, 2026
CVE-2026-18759 UNKNOWN The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by AES encryption. Because the … Aug 04, 2026
CVE-2026-18755 HIGH 7.3 A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to execute arbitrary code. By placing … Aug 04, 2026
CVE-2026-18754 CRITICAL 9.1 The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows … Aug 04, 2026
CVE-2026-18753 CRITICAL 9.1 The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows … Aug 04, 2026
CVE-2026-64565 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() The `ims_pcu_process_data()` processes incoming URB data byte by … Aug 04, 2026
CVE-2026-64564 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the … Aug 04, 2026
CVE-2026-64563 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhashtable_walk_start_check() has two restart paths when resuming a … Aug 04, 2026
CVE-2026-64562 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR free_nested() frees the shadow VMCS while vmcs01 … Aug 04, 2026
CVE-2026-64561 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" … Aug 04, 2026
CVE-2026-16623 HIGH 8.0 The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, allowing a multisite … Aug 04, 2026
CVE-2026-16618 CRITICAL 9.8 The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the … Aug 04, 2026
CVE-2026-16548 MEDIUM 5.4 The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin before 1.8.2 does not validate the type, extension, … Aug 04, 2026
CVE-2026-16547 MEDIUM 5.9 The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log entry being requested, nor … Aug 04, 2026
CVE-2026-16546 MEDIUM 4.3 The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJAX actions, and does not verify that … Aug 04, 2026
CVE-2026-16536 MEDIUM 5.3 The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unauthenticated attackers … Aug 04, 2026
CVE-2026-16296 MEDIUM 4.7 The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect handler, passing a decoded request URI to … Aug 04, 2026
CVE-2026-16295 MEDIUM 4.3 The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch paths, allowing any authenticated user such … Aug 04, 2026
CVE-2026-16293 MEDIUM 6.8 The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which could allow users … Aug 04, 2026
CVE-2026-16070 LOW 2.7 The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updating a template's type meta, validating a request … Aug 04, 2026