Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42183
Total
3433
Critical
12465
High
12416
Medium
CVE ID Severity Score Description Published
CVE-2026-82393 HIGH 7.5 pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts … Aug 31, 2026
CVE-2026-77353 MEDIUM 4.6 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos allows authenticated users to inject arbitrary iCalendar properties and events into their … Aug 31, 2026
CVE-2026-77352 MEDIUM 4.3 Wallos is an open-source, self-hostable personal subscription tracker. From version 2.0.0 to before version 5.0.0, any authenticated Wallos user (no admin rights required) can make … Aug 31, 2026
CVE-2026-77351 LOW 3.5 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated user store an arbitrary SMTP host — including private … Aug 31, 2026
CVE-2026-77348 HIGH 8.2 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php … Aug 31, 2026
CVE-2026-83596 HIGH 8.8 A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling. Aug 31, 2026
CVE-2026-82919 HIGH 7.3 A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the file views.py of the component … Aug 31, 2026
CVE-2026-82914 HIGH 7.3 A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument Contact … Aug 31, 2026
CVE-2026-82909 MEDIUM 4.3 A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component … Aug 31, 2026
CVE-2026-82908 HIGH 8.8 A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the … Aug 31, 2026
CVE-2026-82906 LOW 3.7 A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the file src/BE/web/Controllers/Chats/Files/FileController.cs of the component Signed File … Aug 31, 2026
CVE-2026-82852 MEDIUM 5.4 Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions. Aug 31, 2026
CVE-2026-82392 HIGH 7.1 pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name … Aug 31, 2026
CVE-2026-82346 UNKNOWN A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to … Aug 31, 2026
CVE-2026-82229 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions. Aug 31, 2026
CVE-2026-82228 HIGH 8.1 Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions. Aug 31, 2026
CVE-2026-82226 CRITICAL 9.8 Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions. Aug 31, 2026
CVE-2026-82225 HIGH 7.4 Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions. Aug 31, 2026
CVE-2026-82224 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions. Aug 31, 2026
CVE-2026-82221 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions. Aug 31, 2026
CVE-2026-81892 HIGH 8.1 EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single … Aug 31, 2026
CVE-2026-81891 HIGH 8.1 elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the … Aug 31, 2026
CVE-2026-81890 MEDIUM 5.4 elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinderConnector::$csrfProtectedCmds in … Aug 31, 2026
CVE-2026-81889 HIGH 8.6 elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side … Aug 31, 2026
CVE-2026-81888 MEDIUM 5.4 @hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is … Aug 31, 2026