Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42183
Total
3433
Critical
12465
High
12416
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-82393 | HIGH | 7.5 | pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts … | Aug 31, 2026 |
| CVE-2026-77353 | MEDIUM | 4.6 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos allows authenticated users to inject arbitrary iCalendar properties and events into their … | Aug 31, 2026 |
| CVE-2026-77352 | MEDIUM | 4.3 | Wallos is an open-source, self-hostable personal subscription tracker. From version 2.0.0 to before version 5.0.0, any authenticated Wallos user (no admin rights required) can make … | Aug 31, 2026 |
| CVE-2026-77351 | LOW | 3.5 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated user store an arbitrary SMTP host — including private … | Aug 31, 2026 |
| CVE-2026-77348 | HIGH | 8.2 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php … | Aug 31, 2026 |
| CVE-2026-83596 | HIGH | 8.8 | A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling. | Aug 31, 2026 |
| CVE-2026-82919 | HIGH | 7.3 | A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the file views.py of the component … | Aug 31, 2026 |
| CVE-2026-82914 | HIGH | 7.3 | A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument Contact … | Aug 31, 2026 |
| CVE-2026-82909 | MEDIUM | 4.3 | A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component … | Aug 31, 2026 |
| CVE-2026-82908 | HIGH | 8.8 | A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the … | Aug 31, 2026 |
| CVE-2026-82906 | LOW | 3.7 | A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the file src/BE/web/Controllers/Chats/Files/FileController.cs of the component Signed File … | Aug 31, 2026 |
| CVE-2026-82852 | MEDIUM | 5.4 | Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions. | Aug 31, 2026 |
| CVE-2026-82392 | HIGH | 7.1 | pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name … | Aug 31, 2026 |
| CVE-2026-82346 | UNKNOWN | — | A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to … | Aug 31, 2026 |
| CVE-2026-82229 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions. | Aug 31, 2026 |
| CVE-2026-82228 | HIGH | 8.1 | Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions. | Aug 31, 2026 |
| CVE-2026-82226 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions. | Aug 31, 2026 |
| CVE-2026-82225 | HIGH | 7.4 | Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions. | Aug 31, 2026 |
| CVE-2026-82224 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions. | Aug 31, 2026 |
| CVE-2026-82221 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions. | Aug 31, 2026 |
| CVE-2026-81892 | HIGH | 8.1 | EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single … | Aug 31, 2026 |
| CVE-2026-81891 | HIGH | 8.1 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the … | Aug 31, 2026 |
| CVE-2026-81890 | MEDIUM | 5.4 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinderConnector::$csrfProtectedCmds in … | Aug 31, 2026 |
| CVE-2026-81889 | HIGH | 8.6 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side … | Aug 31, 2026 |
| CVE-2026-81888 | MEDIUM | 5.4 | @hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is … | Aug 31, 2026 |