Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50353
Total
4061
Critical
14946
High
14711
Medium
CVE ID Severity Score Description Published
CVE-2026-17561 CRITICAL 9.8 Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue … Jul 31, 2026
CVE-2026-15227 UNKNOWN — Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" permission to modify reports owned by … Jul 31, 2026
CVE-2026-46594 UNKNOWN — A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a specially crafted … Jul 31, 2026
CVE-2026-46593 UNKNOWN — A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint … Jul 31, 2026
CVE-2025-67651 UNKNOWN — A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an … Jul 31, 2026
CVE-2025-67650 UNKNOWN — An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible … Jul 31, 2026
CVE-2025-67649 UNKNOWN — A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible … Jul 31, 2026
CVE-2026-64607 MEDIUM 5.3 HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or … Jul 31, 2026
CVE-2026-62391 HIGH 8.1 The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist … Jul 31, 2026
CVE-2026-44615 MEDIUM 6.5 Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a note, or access to folder operations, could … Jul 31, 2026
CVE-2026-17567 MEDIUM 5.3 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all … Jul 31, 2026
CVE-2026-16843 HIGH 7.2 Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by … Jul 31, 2026
CVE-2026-18437 MEDIUM 5.3 The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the … Jul 31, 2026
CVE-2026-18436 MEDIUM 5.3 The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign/<id>/restore-revision/<revision_id>). … Jul 31, 2026
CVE-2026-15722 HIGH 7.5 A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval … Jul 31, 2026
CVE-2026-11770 HIGH 7.5 A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because … Jul 31, 2026
CVE-2026-10079 HIGH 8.5 A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the … Jul 31, 2026
CVE-2026-65313 HIGH 8.1 A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to … Jul 31, 2026
CVE-2026-65311 MEDIUM 5.3 The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target … Jul 31, 2026
CVE-2026-65310 HIGH 7.5 ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on … Jul 31, 2026
CVE-2026-65309 HIGH 7.5 ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows … Jul 31, 2026
CVE-2026-18218 MEDIUM 4.2 A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application … Jul 31, 2026
CVE-2026-18217 LOW 3.4 A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML … Jul 31, 2026
CVE-2026-18215 MEDIUM 6.8 Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where … Jul 31, 2026
CVE-2026-18214 MEDIUM 6.8 Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was … Jul 31, 2026