Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50855
Total
4075
Critical
15116
High
14809
Medium
CVE ID Severity Score Description Published
CVE-2026-66748 HIGH 8.8 Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code … Jul 28, 2026
CVE-2026-66746 MEDIUM 5.4 Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote attackers to inject arbitrary response headers by embedding carriage return (0x0D) or … Jul 28, 2026
CVE-2026-62828 MEDIUM 5.4 Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network. Jul 28, 2026
CVE-2026-61609 HIGH 7.5 Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProvider::configureRateLimiting() applied a single global bucket … Jul 28, 2026
CVE-2026-54593 HIGH 8.1 Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid … Jul 28, 2026
CVE-2026-54545 HIGH 7.1 wakaru is a JavaScript decompiler and unminifier toolkit. From 1.0.0 until 1.4.0, @wakaru/cli sanitizes bundle-controlled module filenames only once before writing extracted modules, so a … Jul 28, 2026
CVE-2026-51271 CRITICAL 9.6 In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the WAV header parsing function read_WAV_Header(). The function reads untrusted chunk size and bytes-to-skip … Jul 28, 2026
CVE-2026-51270 UNKNOWN — schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the htmlToUTF8() HTML entity decoding function. The function parses attacker-controlled malicious HTML entities and uses … Jul 28, 2026
CVE-2026-51269 HIGH 8.8 schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the connecttospeech() function. The application accepts attacker-controlled long speech text input, performs URL encoding, and … Jul 28, 2026
CVE-2026-51268 UNKNOWN — schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the host parsing logic. The dismantle_host() function parses untrusted host and URL input, and subsequent … Jul 28, 2026
CVE-2026-51267 CRITICAL 9.8 schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the URL path concatenation and encoding module. The application splices untrusted extension path and attacker-controlled … Jul 28, 2026
CVE-2026-51266 CRITICAL 9.8 schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the HTTP request header construction logic. The application dynamically splices attacker-controlled host name, path, query … Jul 28, 2026
CVE-2026-51263 CRITICAL 9.8 schreibfaul1 ESP32-audioI2S 3.4.5 is vulnerable to Buffer Overflow. The Audio::openai_speech function in the Audio library manually constructs JSON request bodies and HTTP request headers by … Jul 28, 2026
CVE-2026-47483 HIGH 8.2 NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated … Jul 28, 2026
CVE-2026-47427 HIGH 7.5 GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is nil, … Jul 28, 2026
CVE-2026-45293 HIGH 8.6 WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the … Jul 28, 2026
CVE-2026-43910 HIGH 8.2 Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2.1 until 10.1.1, when directConnect(true) … Jul 28, 2026
CVE-2026-8164 HIGH 7.3 Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Order Hijacking. This issue affects ArkSigner … Jul 28, 2026
CVE-2026-7521 MEDIUM 5.5 Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin with … Jul 28, 2026
CVE-2026-6879 UNKNOWN — `Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` … Jul 28, 2026
CVE-2026-67178 UNKNOWN — MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrectly formatted HTTP-to-HTTPS redirect: Redirect permanent / https://misp.example Apache’s Redirect directive appends any portion … Jul 28, 2026
CVE-2026-67174 UNKNOWN — Pivotick contains a DOM-based cross-site scripting vulnerability in its generic UI element resolution and icon-rendering utilities. The tryResolveHTMLElement function treated any resolved string as HTML … Jul 28, 2026
CVE-2026-66713 CRITICAL 9.8 Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat (only when Tribes clustering … Jul 28, 2026
CVE-2026-66299 HIGH 7.5 Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 … Jul 28, 2026
CVE-2026-63727 HIGH 8.8 Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is … Jul 28, 2026