Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50129
Total
4051
Critical
14904
High
14658
Medium
CVE ID Severity Score Description Published
CVE-2026-41453 HIGH 8.8 Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL … Aug 03, 2026
CVE-2026-41452 CRITICAL 9.8 Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending … Aug 03, 2026
CVE-2026-39932 CRITICAL 9.1 OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system … Aug 03, 2026
CVE-2026-39931 HIGH 7.2 OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that allows administrators with admin or super ACL privileges to … Aug 03, 2026
CVE-2026-18718 HIGH 7.0 Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by supplying a malicious Ghidra … Aug 03, 2026
CVE-2026-18610 MEDIUM 5.3 A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.aspx. The manipulation results in improper authentication. … Aug 03, 2026
CVE-2026-18607 HIGH 8.8 A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 … Aug 03, 2026
CVE-2026-18606 HIGH 7.8 A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)\Razer\RzUpdateEngineService\RzUpdateService.exe of the … Aug 03, 2026
CVE-2026-18605 HIGH 7.0 A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown function in the library AppCheckD.sys of the component Kernel Mini-Filter … Aug 03, 2026
CVE-2026-18604 MEDIUM 5.3 A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. … Aug 03, 2026
CVE-2026-18602 CRITICAL 9.8 A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. … Aug 03, 2026
CVE-2026-18477 MEDIUM 4.4 A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed … Aug 03, 2026
CVE-2026-18243 UNKNOWN Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews. Aug 03, 2026
CVE-2026-18651 MEDIUM 5.4 A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the … Aug 03, 2026
CVE-2026-18568 HIGH 7.5 XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check. … Aug 03, 2026
CVE-2026-18508 MEDIUM 4.4 A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory … Aug 03, 2026
CVE-2026-18248 CRITICAL 9.1 @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications are documented to use for authorization decisions such as reading API … Aug 03, 2026
CVE-2026-15430 MEDIUM 6.2 Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to … Aug 03, 2026
CVE-2026-67609 HIGH 7.8 Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalation vulnerability that allows attackers with access to … Aug 03, 2026
CVE-2026-9487 CRITICAL 9.1 XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolves the SignedInfo Reference/@URI to a node … Aug 03, 2026
CVE-2026-9390 CRITICAL 9.1 XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions by concatenating the SignedInfo/Reference/@URI value … Aug 03, 2026
CVE-2026-69097 HIGH 7.0 GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers … Aug 03, 2026
CVE-2026-69096 HIGH 8.8 OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's … Aug 03, 2026
CVE-2026-69095 HIGH 7.5 OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured … Aug 03, 2026
CVE-2026-69094 MEDIUM 4.3 Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php that allows authenticated users to hijack list configurations. Attackers … Aug 03, 2026