Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50589
Total
4065
Critical
14978
High
14744
Medium
CVE ID Severity Score Description Published
CVE-2026-57859 HIGH 7.5 e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band database write access to … Jul 30, 2026
CVE-2026-56428 HIGH 8.1 The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public … Jul 30, 2026
CVE-2026-41709 LOW 2.7 VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged. Jul 30, 2026
CVE-2026-12722 HIGH 8.2 Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. This issue affects FTC E-Commerce Management Panel: … Jul 30, 2026
CVE-2026-59310 CRITICAL 9.8 VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute … Jul 30, 2026
CVE-2026-59309 CRITICAL 9.8 VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to … Jul 30, 2026
CVE-2026-54368 HIGH 8.8 CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to execute arbitrary SQL statements by supplying a crafted … Jul 30, 2026
CVE-2026-54367 HIGH 8.6 CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints … Jul 30, 2026
CVE-2026-54366 HIGH 7.5 CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary files by supplying a malicious URL to … Jul 30, 2026
CVE-2026-54365 HIGH 7.5 CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted … Jul 30, 2026
CVE-2026-54364 MEDIUM 6.5 CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inject arbitrary session variables by embedding newline and tab characters into … Jul 30, 2026
CVE-2026-54363 CRITICAL 9.1 CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used … Jul 30, 2026
CVE-2026-47876 CRITICAL 9.3 VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with … Jul 30, 2026
CVE-2026-41703 HIGH 7.6 VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to … Jul 30, 2026
CVE-2026-7260 UNKNOWN — Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* … Jul 30, 2026
CVE-2026-5582 MEDIUM 4.3 The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24.2. This is due to missing nonce … Jul 30, 2026
CVE-2026-18382 MEDIUM 6.8 A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token … Jul 30, 2026
CVE-2026-18381 HIGH 7.6 A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to … Jul 30, 2026
CVE-2026-18378 HIGH 7.6 A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When … Jul 30, 2026
CVE-2026-17544 UNKNOWN — Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* … Jul 30, 2026
CVE-2026-17543 UNKNOWN — Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from … Jul 30, 2026
CVE-2026-15397 HIGH 7.2 The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the … Jul 30, 2026
CVE-2026-22622 HIGH 8.8 Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges … Jul 30, 2026
CVE-2026-22621 HIGH 8.3 Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary … Jul 30, 2026
CVE-2026-22620 HIGH 8.6 Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain … Jul 30, 2026