Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50663
Total
4071
Critical
15059
High
14768
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-62363 | MEDIUM | 5.0 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in … | Jul 30, 2026 |
| CVE-2026-62343 | MEDIUM | 4.7 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, … | Jul 30, 2026 |
| CVE-2026-16339 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Jul 29, 2026 |
| CVE-2026-67595 | HIGH | 8.1 | VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers … | Jul 29, 2026 |
| CVE-2026-18060 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this … | Jul 29, 2026 |
| CVE-2026-15157 | MEDIUM | 4.2 | undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In … | Jul 29, 2026 |
| CVE-2026-14643 | MEDIUM | 5.9 | undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. In undici from 7.0.0 up to … | Jul 29, 2026 |
| CVE-2025-69949 | HIGH | 7.3 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email. | Jul 29, 2026 |
| CVE-2025-69945 | HIGH | 7.3 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1. | Jul 29, 2026 |
| CVE-2025-69944 | UNKNOWN | — | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter. | Jul 29, 2026 |
| CVE-2025-69943 | CRITICAL | 9.8 | kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid. | Jul 29, 2026 |
| CVE-2025-69942 | UNKNOWN | — | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1. | Jul 29, 2026 |
| CVE-2025-67408 | HIGH | 7.3 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status. | Jul 29, 2026 |
| CVE-2025-67407 | HIGH | 7.3 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class. | Jul 29, 2026 |
| CVE-2025-67406 | HIGH | 7.3 | https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). The component is: control/activate_case.php,?id=1. The attack vector … | Jul 29, 2026 |
| CVE-2025-67405 | HIGH | 7.3 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password. | Jul 29, 2026 |
| CVE-2025-67404 | CRITICAL | 9.8 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class. | Jul 29, 2026 |
| CVE-2025-67403 | CRITICAL | 9.8 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name. | Jul 29, 2026 |
| CVE-2026-67439 | MEDIUM | 4.3 | OliveTin gives safe and simple access to predefined shell commands from a web interface. Prior to 3000.17.0, the service/internal/api/api.go StartActionAndWait and StartActionByGetAndWait endpoints return full … | Jul 29, 2026 |
| CVE-2026-67438 | MEDIUM | 6.6 | OliveTin gives access to predefined shell commands from a web interface. From 3000.2.0 until 3000.17.0, the service/internal/executor/arguments.go checkShellArgumentSafety function does not treat regex: custom argument … | Jul 29, 2026 |
| CVE-2026-67437 | HIGH | 7.5 | OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the … | Jul 29, 2026 |
| CVE-2026-65975 | MEDIUM | 6.5 | Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 up to but not including 1.107.1 and … | Jul 29, 2026 |
| CVE-2026-54249 | MEDIUM | 6.8 | Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits … | Jul 29, 2026 |
| CVE-2026-50782 | UNKNOWN | — | Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp endpoint. An unauthenticated remote attacker can send a crafted XML payload … | Jul 29, 2026 |
| CVE-2026-46678 | MEDIUM | 6.8 | Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when an application opts a URL into force_download='allow-local' … | Jul 29, 2026 |