Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50663
Total
4071
Critical
15059
High
14768
Medium
CVE ID Severity Score Description Published
CVE-2026-62363 MEDIUM 5.0 ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in … Jul 30, 2026
CVE-2026-62343 MEDIUM 4.7 ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, … Jul 30, 2026
CVE-2026-16339 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Jul 29, 2026
CVE-2026-67595 HIGH 8.1 VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers … Jul 29, 2026
CVE-2026-18060 UNKNOWN — Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this … Jul 29, 2026
CVE-2026-15157 MEDIUM 4.2 undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In … Jul 29, 2026
CVE-2026-14643 MEDIUM 5.9 undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. In undici from 7.0.0 up to … Jul 29, 2026
CVE-2025-69949 HIGH 7.3 kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email. Jul 29, 2026
CVE-2025-69945 HIGH 7.3 kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1. Jul 29, 2026
CVE-2025-69944 UNKNOWN — kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter. Jul 29, 2026
CVE-2025-69943 CRITICAL 9.8 kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid. Jul 29, 2026
CVE-2025-69942 UNKNOWN — kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1. Jul 29, 2026
CVE-2025-67408 HIGH 7.3 Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status. Jul 29, 2026
CVE-2025-67407 HIGH 7.3 Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class. Jul 29, 2026
CVE-2025-67406 HIGH 7.3 https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). The component is: control/activate_case.php,?id=1. The attack vector … Jul 29, 2026
CVE-2025-67405 HIGH 7.3 Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password. Jul 29, 2026
CVE-2025-67404 CRITICAL 9.8 Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class. Jul 29, 2026
CVE-2025-67403 CRITICAL 9.8 Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name. Jul 29, 2026
CVE-2026-67439 MEDIUM 4.3 OliveTin gives safe and simple access to predefined shell commands from a web interface. Prior to 3000.17.0, the service/internal/api/api.go StartActionAndWait and StartActionByGetAndWait endpoints return full … Jul 29, 2026
CVE-2026-67438 MEDIUM 6.6 OliveTin gives access to predefined shell commands from a web interface. From 3000.2.0 until 3000.17.0, the service/internal/executor/arguments.go checkShellArgumentSafety function does not treat regex: custom argument … Jul 29, 2026
CVE-2026-67437 HIGH 7.5 OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the … Jul 29, 2026
CVE-2026-65975 MEDIUM 6.5 Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 up to but not including 1.107.1 and … Jul 29, 2026
CVE-2026-54249 MEDIUM 6.8 Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits … Jul 29, 2026
CVE-2026-50782 UNKNOWN — Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp endpoint. An unauthenticated remote attacker can send a crafted XML payload … Jul 29, 2026
CVE-2026-46678 MEDIUM 6.8 Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when an application opts a URL into force_download='allow-local' … Jul 29, 2026