Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50129
Total
4051
Critical
14904
High
14658
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-2346 | CRITICAL | 9.8 | Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack. This issue affects Mobile App: through 12.05.2026. | Aug 03, 2026 |
| CVE-2026-18599 | HIGH | 8.0 | A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/logread of the component … | Aug 03, 2026 |
| CVE-2026-18598 | HIGH | 8.8 | A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_log of the file /usr/lib/oui-httpd/rpc/logread of the component Logread … | Aug 03, 2026 |
| CVE-2026-18574 | UNKNOWN | — | An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access … | Aug 03, 2026 |
| CVE-2026-69082 | UNKNOWN | — | CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. The /account/delete/<id> endpoint accepted HTTP GET requests for an operation that modified … | Aug 03, 2026 |
| CVE-2026-69079 | UNKNOWN | — | CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint accepts a user-controlled days query parameter that was not restricted to a … | Aug 03, 2026 |
| CVE-2026-69078 | UNKNOWN | — | CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functionality. User-controlled CTI content, including conversion names, descriptions, and comments, is … | Aug 03, 2026 |
| CVE-2026-68742 | MEDIUM | 5.5 | A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. … | Aug 03, 2026 |
| CVE-2026-33591 | UNKNOWN | — | A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a … | Aug 03, 2026 |
| CVE-2026-0392 | UNKNOWN | — | eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is not authenticated or integrity-protected. On each launch … | Aug 03, 2026 |
| CVE-2026-69075 | UNKNOWN | — | FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-controlled fields. Persisted values—including case titles, ticket identifiers, recurring-case information, user profile … | Aug 03, 2026 |
| CVE-2026-63563 | MEDIUM | 6.5 | Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When … | Aug 03, 2026 |
| CVE-2026-63545 | LOW | 2.4 | Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users. | Aug 03, 2026 |
| CVE-2026-62416 | MEDIUM | 5.3 | Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly. When the … | Aug 03, 2026 |
| CVE-2026-60011 | MEDIUM | 5.3 | Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product. | Aug 03, 2026 |
| CVE-2026-8794 | UNKNOWN | — | PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring … | Aug 03, 2026 |
| CVE-2026-8793 | UNKNOWN | — | PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force … | Aug 03, 2026 |
| CVE-2026-28147 | MEDIUM | 5.4 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects … | Aug 03, 2026 |
| CVE-2026-21555 | HIGH | 7.5 | In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | Aug 03, 2026 |
| CVE-2026-21554 | HIGH | 7.5 | In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | Aug 03, 2026 |
| CVE-2026-21553 | HIGH | 7.5 | In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | Aug 03, 2026 |
| CVE-2026-21552 | HIGH | 7.5 | In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | Aug 03, 2026 |
| CVE-2026-21551 | HIGH | 7.5 | In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | Aug 03, 2026 |
| CVE-2026-21550 | HIGH | 7.5 | In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | Aug 03, 2026 |
| CVE-2026-21549 | HIGH | 7.5 | In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed | Aug 03, 2026 |