Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42183
Total
3433
Critical
12465
High
12416
Medium
CVE ID Severity Score Description Published
CVE-2026-82731 UNKNOWN URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an attacker who controls a path-parameter value to redirect a generated client's request, … Sep 01, 2026
CVE-2026-82730 UNKNOWN Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute values that Ash field policies denied. When a field policy denies … Sep 01, 2026
CVE-2026-77950 UNKNOWN Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to receive unredacted internal error data by provoking an error … Sep 01, 2026
CVE-2026-77856 UNKNOWN Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node … Sep 01, 2026
CVE-2026-75865 CRITICAL 9.8 The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file … Sep 01, 2026
CVE-2026-74837 UNKNOWN Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node … Sep 01, 2026
CVE-2026-67395 MEDIUM 5.9 A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation of file path parameters. By leveraging directory traversal … Sep 01, 2026
CVE-2026-67394 UNKNOWN A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and … Sep 01, 2026
CVE-2026-65643 UNKNOWN Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root. Sep 01, 2026
CVE-2026-48932 LOW 3.7 A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while … Sep 01, 2026
CVE-2026-18743 LOW 2.5 A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead … Sep 01, 2026
CVE-2026-19820 UNKNOWN A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows … Sep 01, 2026
CVE-2026-83524 CRITICAL 9.9 A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the … Aug 31, 2026
CVE-2026-82971 CRITICAL 10.0 A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of … Aug 31, 2026
CVE-2026-4560 UNKNOWN Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this … Aug 31, 2026
CVE-2026-82957 HIGH 7.3 A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook … Aug 31, 2026
CVE-2026-82954 CRITICAL 9.9 A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation … Aug 31, 2026
CVE-2026-82922 HIGH 7.3 A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the function flow_update_cart of the file /flow.php?step=update_cart. The manipulation of … Aug 31, 2026
CVE-2026-82921 HIGH 7.3 A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the file admin/pack.php. Executing a manipulation of the … Aug 31, 2026
CVE-2026-82882 HIGH 8.8 Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated … Aug 31, 2026
CVE-2026-82398 UNKNOWN pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py … Aug 31, 2026
CVE-2026-82397 HIGH 7.5 Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. … Aug 31, 2026
CVE-2026-82396 MEDIUM 5.4 Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, src/Sulu/Bundle/MediaBundle/Controller/MediaStreamController.php allows the /media/{id}/download/{slug} route and … Aug 31, 2026
CVE-2026-82395 UNKNOWN Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the media move endpoint derives its … Aug 31, 2026
CVE-2026-82394 UNKNOWN Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the preview-link endpoint and src/Sulu/Bundle/PreviewBundle/Application/Manager/PreviewLinkManager.php do … Aug 31, 2026