Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50129
Total
4051
Critical
14904
High
14658
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-18615 | CRITICAL | 9.8 | A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bin/glc of the component wg-server.so … | Aug 03, 2026 |
| CVE-2026-18614 | CRITICAL | 9.8 | A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. … | Aug 03, 2026 |
| CVE-2025-15631 | UNKNOWN | — | A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An … | Aug 03, 2026 |
| CVE-2025-15630 | UNKNOWN | — | A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a … | Aug 03, 2026 |
| CVE-2025-15629 | UNKNOWN | — | A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable … | Aug 03, 2026 |
| CVE-2025-15628 | UNKNOWN | — | Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the … | Aug 03, 2026 |
| CVE-2025-15627 | UNKNOWN | — | A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers … | Aug 03, 2026 |
| CVE-2025-15544 | UNKNOWN | — | A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm … | Aug 03, 2026 |
| CVE-2026-61524 | HIGH | 7.2 | WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated administrators to achieve remote code execution by … | Aug 03, 2026 |
| CVE-2026-61523 | HIGH | 7.2 | WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arbitrary PHP code by submitting malicious … | Aug 03, 2026 |
| CVE-2026-40717 | MEDIUM | 6.6 | Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially … | Aug 03, 2026 |
| CVE-2026-18613 | CRITICAL | 9.8 | A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so … | Aug 03, 2026 |
| CVE-2026-18612 | CRITICAL | 9.8 | A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the file /cgi-bin/glc of the component plugins.so … | Aug 03, 2026 |
| CVE-2025-9291 | UNKNOWN | — | A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate … | Aug 03, 2026 |
| CVE-2026-69153 | UNKNOWN | — | PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior … | Aug 03, 2026 |
| CVE-2026-69152 | HIGH | 7.5 | The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while … | Aug 03, 2026 |
| CVE-2026-69151 | UNKNOWN | — | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular … | Aug 03, 2026 |
| CVE-2026-69149 | UNKNOWN | — | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.7, a Cross-Site … | Aug 03, 2026 |
| CVE-2026-68945 | UNKNOWN | — | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins … | Aug 03, 2026 |
| CVE-2026-68930 | MEDIUM | 6.5 | Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened … | Aug 03, 2026 |
| CVE-2026-68869 | UNKNOWN | — | Rejected reason: This CVE ID was assigned in error. Upon further review, the reported issue does not represent a security vulnerability and does not require … | Aug 03, 2026 |
| CVE-2026-67612 | MEDIUM | 4.8 | OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that allows authenticated administrators to inject arbitrary HTML and JavaScript … | Aug 03, 2026 |
| CVE-2026-67611 | HIGH | 8.1 | OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant … | Aug 03, 2026 |
| CVE-2026-67610 | HIGH | 8.1 | OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with … | Aug 03, 2026 |
| CVE-2026-61372 | HIGH | 7.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena Fuseki: through 6.1.0. Users … | Aug 03, 2026 |