Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50855
Total
4075
Critical
15116
High
14809
Medium
CVE ID Severity Score Description Published
CVE-2026-55555 UNKNOWN — Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack through the manipulation of … Jul 28, 2026
CVE-2026-55554 UNKNOWN — Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot boundaries with a strpos() prefix check … Jul 28, 2026
CVE-2026-48060 HIGH 8.1 Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in conjunction with CSRF protection … Jul 28, 2026
CVE-2026-3158 MEDIUM 4.3 IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, … Jul 28, 2026
CVE-2026-3157 MEDIUM 4.3 IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, … Jul 28, 2026
CVE-2026-1918 MEDIUM 4.9 IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, … Jul 28, 2026
CVE-2026-16347 HIGH 8.8 MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, … Jul 28, 2026
CVE-2026-16192 HIGH 7.1 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service vulnerability when the restConnector-2.0 feature is enabled. Jul 28, 2026
CVE-2026-16184 HIGH 7.0 IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request. Jul 28, 2026
CVE-2026-16107 MEDIUM 5.9 IBM TS4500 CLI tool Versions: 0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive … Jul 28, 2026
CVE-2026-11391 MEDIUM 6.3 Tanium addressed a SQL injection vulnerability in Patch. Jul 28, 2026
CVE-2026-7769 HIGH 8.1 IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, … Jul 28, 2026
CVE-2026-7362 MEDIUM 4.3 IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 could allow … Jul 28, 2026
CVE-2026-66745 HIGH 7.5 Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated attackers to hijack administrative sessions by … Jul 28, 2026
CVE-2026-5114 MEDIUM 4.9 The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and including, 1.3.8. This is due … Jul 28, 2026
CVE-2026-59932 HIGH 7.5 PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through … Jul 28, 2026
CVE-2026-50738 UNKNOWN — A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced after the underlying slot has been freed or recycled … Jul 28, 2026
CVE-2026-50737 UNKNOWN — When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressions on the subscriber. Because … Jul 28, 2026
CVE-2026-50736 UNKNOWN — The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads on the subscriber … Jul 28, 2026
CVE-2026-50735 UNKNOWN — pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol messages before copying them, resulting in an out-of-bounds read. … Jul 28, 2026
CVE-2026-4932 MEDIUM 4.2 IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to … Jul 28, 2026
CVE-2026-4912 MEDIUM 4.1 The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.0.3. This is … Jul 28, 2026
CVE-2026-49258 HIGH 8.8 Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply … Jul 28, 2026
CVE-2026-48396 HIGH 8.6 Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could … Jul 28, 2026
CVE-2026-48395 HIGH 8.6 Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An attacker … Jul 28, 2026