Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50589
Total
4065
Critical
14978
High
14744
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-57859 | HIGH | 7.5 | e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band database write access to … | Jul 30, 2026 |
| CVE-2026-56428 | HIGH | 8.1 | The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public … | Jul 30, 2026 |
| CVE-2026-41709 | LOW | 2.7 | VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged. | Jul 30, 2026 |
| CVE-2026-12722 | HIGH | 8.2 | Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. This issue affects FTC E-Commerce Management Panel: … | Jul 30, 2026 |
| CVE-2026-59310 | CRITICAL | 9.8 | VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute … | Jul 30, 2026 |
| CVE-2026-59309 | CRITICAL | 9.8 | VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to … | Jul 30, 2026 |
| CVE-2026-54368 | HIGH | 8.8 | CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to execute arbitrary SQL statements by supplying a crafted … | Jul 30, 2026 |
| CVE-2026-54367 | HIGH | 8.6 | CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints … | Jul 30, 2026 |
| CVE-2026-54366 | HIGH | 7.5 | CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary files by supplying a malicious URL to … | Jul 30, 2026 |
| CVE-2026-54365 | HIGH | 7.5 | CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted … | Jul 30, 2026 |
| CVE-2026-54364 | MEDIUM | 6.5 | CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inject arbitrary session variables by embedding newline and tab characters into … | Jul 30, 2026 |
| CVE-2026-54363 | CRITICAL | 9.1 | CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used … | Jul 30, 2026 |
| CVE-2026-47876 | CRITICAL | 9.3 | VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with … | Jul 30, 2026 |
| CVE-2026-41703 | HIGH | 7.6 | VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to … | Jul 30, 2026 |
| CVE-2026-7260 | UNKNOWN | — | Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* … | Jul 30, 2026 |
| CVE-2026-5582 | MEDIUM | 4.3 | The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24.2. This is due to missing nonce … | Jul 30, 2026 |
| CVE-2026-18382 | MEDIUM | 6.8 | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token … | Jul 30, 2026 |
| CVE-2026-18381 | HIGH | 7.6 | A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to … | Jul 30, 2026 |
| CVE-2026-18378 | HIGH | 7.6 | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When … | Jul 30, 2026 |
| CVE-2026-17544 | UNKNOWN | — | Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* … | Jul 30, 2026 |
| CVE-2026-17543 | UNKNOWN | — | Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from … | Jul 30, 2026 |
| CVE-2026-15397 | HIGH | 7.2 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.0.0. This is due to the … | Jul 30, 2026 |
| CVE-2026-22622 | HIGH | 8.8 | Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges … | Jul 30, 2026 |
| CVE-2026-22621 | HIGH | 8.3 | Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary … | Jul 30, 2026 |
| CVE-2026-22620 | HIGH | 8.6 | Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain … | Jul 30, 2026 |