Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50169
Total
4054
Critical
14909
High
14667
Medium
CVE ID Severity Score Description Published
CVE-2026-54729 UNKNOWN DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as … Jul 31, 2026
CVE-2026-54725 CRITICAL 9.6 vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap … Jul 31, 2026
CVE-2026-34497 UNKNOWN Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue … Jul 31, 2026
CVE-2026-34495 UNKNOWN Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems … Jul 31, 2026
CVE-2026-34490 UNKNOWN Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve … Jul 31, 2026
CVE-2026-21662 UNKNOWN Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before … Jul 31, 2026
CVE-2026-67822 CRITICAL 9.8 Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters … Jul 31, 2026
CVE-2026-58048 UNKNOWN Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. Jul 31, 2026
CVE-2026-58047 UNKNOWN HTTP Smuggling in cPanel allows potential leak of credentials. Jul 31, 2026
CVE-2026-54707 MEDIUM 5.4 OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior … Jul 31, 2026
CVE-2026-54706 MEDIUM 4.8 OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior … Jul 31, 2026
CVE-2026-52856 HIGH 7.5 Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP … Jul 31, 2026
CVE-2026-52855 CRITICAL 9.9 Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow … Jul 31, 2026
CVE-2026-67607 MEDIUM 5.9 LightFTP 2.3.1 contains a race condition vulnerability that allows remote attackers to crash the server by racing a fresh connection that reuses the FTP context … Jul 31, 2026
CVE-2026-59232 UNKNOWN Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead permission to … Jul 31, 2026
CVE-2026-59231 UNKNOWN Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server … Jul 31, 2026
CVE-2026-56571 LOW 3.7 HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network timeout, and … Jul 31, 2026
CVE-2026-56570 LOW 3.7 HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers … Jul 31, 2026
CVE-2026-56569 MEDIUM 4.0 HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application … Jul 31, 2026
CVE-2026-56568 LOW 3.7 HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead … Jul 31, 2026
CVE-2026-56567 MEDIUM 5.1 HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application … Jul 31, 2026
CVE-2026-52857 MEDIUM 5.5 Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, unbounded json, yaml, and xml configuration-file parsers … Jul 31, 2026
CVE-2026-18141 HIGH 8.2 A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security … Jul 31, 2026
CVE-2026-17566 CRITICAL 9.9 pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the … Jul 31, 2026
CVE-2026-17351 CRITICAL 9.0 The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly … Jul 31, 2026