Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50129
Total
4051
Critical
14904
High
14658
Medium
CVE ID Severity Score Description Published
CVE-2026-18615 CRITICAL 9.8 A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bin/glc of the component wg-server.so … Aug 03, 2026
CVE-2026-18614 CRITICAL 9.8 A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. … Aug 03, 2026
CVE-2025-15631 UNKNOWN A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An … Aug 03, 2026
CVE-2025-15630 UNKNOWN A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a … Aug 03, 2026
CVE-2025-15629 UNKNOWN A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable … Aug 03, 2026
CVE-2025-15628 UNKNOWN Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the … Aug 03, 2026
CVE-2025-15627 UNKNOWN A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers … Aug 03, 2026
CVE-2025-15544 UNKNOWN A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm … Aug 03, 2026
CVE-2026-61524 HIGH 7.2 WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated administrators to achieve remote code execution by … Aug 03, 2026
CVE-2026-61523 HIGH 7.2 WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arbitrary PHP code by submitting malicious … Aug 03, 2026
CVE-2026-40717 MEDIUM 6.6 Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially … Aug 03, 2026
CVE-2026-18613 CRITICAL 9.8 A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so … Aug 03, 2026
CVE-2026-18612 CRITICAL 9.8 A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the file /cgi-bin/glc of the component plugins.so … Aug 03, 2026
CVE-2025-9291 UNKNOWN A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate … Aug 03, 2026
CVE-2026-69153 UNKNOWN PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior … Aug 03, 2026
CVE-2026-69152 HIGH 7.5 The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while … Aug 03, 2026
CVE-2026-69151 UNKNOWN Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular … Aug 03, 2026
CVE-2026-69149 UNKNOWN Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.7, a Cross-Site … Aug 03, 2026
CVE-2026-68945 UNKNOWN Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins … Aug 03, 2026
CVE-2026-68930 MEDIUM 6.5 Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened … Aug 03, 2026
CVE-2026-68869 UNKNOWN Rejected reason: This CVE ID was assigned in error. Upon further review, the reported issue does not represent a security vulnerability and does not require … Aug 03, 2026
CVE-2026-67612 MEDIUM 4.8 OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that allows authenticated administrators to inject arbitrary HTML and JavaScript … Aug 03, 2026
CVE-2026-67611 HIGH 8.1 OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant … Aug 03, 2026
CVE-2026-67610 HIGH 8.1 OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with … Aug 03, 2026
CVE-2026-61372 HIGH 7.5 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena Fuseki: through 6.1.0. Users … Aug 03, 2026