Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51159
Total
4081
Critical
15166
High
14812
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-62433 | HIGH | 7.3 | Parts of the DM_OP handling code assumes the caller has provided the required number of buffers for the given operation without any checking being done. … | Jul 28, 2026 |
| CVE-2026-62432 | HIGH | 7.3 | The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without holding the correct lock. It can race with EVTCHNOP_reset, resulting in dereferencing … | Jul 28, 2026 |
| CVE-2026-62431 | HIGH | 7.5 | The logic to handle periodic Viridian STIMERs performs a division with an unchecked user-controlled divisor value, that can be set to zero to cause a … | Jul 28, 2026 |
| CVE-2026-62430 | HIGH | 7.5 | Accesses to the CMOS memory contents are done using an indirect IO port pair. Therefore Xen needs to cache the guest chosen index, and one … | Jul 28, 2026 |
| CVE-2026-62429 | MEDIUM | 6.5 | Accessing the vNUMA configuration data of a guest is still possible when domain destruction has already started. The cleaning up of that configuration information is … | Jul 28, 2026 |
| CVE-2026-62428 | HIGH | 7.8 | When grant-copy operations are processed, the respective grant may or may not already be in use by another operation (a mapping or another copy). For … | Jul 28, 2026 |
| CVE-2026-62427 | HIGH | 8.8 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations … | Jul 28, 2026 |
| CVE-2026-62426 | HIGH | 8.8 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To manage the system, sysctl and platform operations … | Jul 28, 2026 |
| CVE-2026-62425 | MEDIUM | 5.5 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk … | Jul 28, 2026 |
| CVE-2026-62424 | MEDIUM | 5.5 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk … | Jul 28, 2026 |
| CVE-2026-62423 | MEDIUM | 5.5 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk … | Jul 28, 2026 |
| CVE-2026-49332 | HIGH | 8.5 | A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from … | Jul 28, 2026 |
| CVE-2026-42495 | MEDIUM | 5.5 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk … | Jul 28, 2026 |
| CVE-2026-42494 | MEDIUM | 6.1 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The directory and Rock Ridge / SUSP walk … | Jul 28, 2026 |
| CVE-2026-42493 | HIGH | 7.5 | Addressing certain issues, in particular related to operations which may take excessively long and therefore would need preemption, has turned out overly costly. Since alternatives … | Jul 28, 2026 |
| CVE-2026-42492 | HIGH | 7.5 | Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To make this more robust, a new … | Jul 28, 2026 |
| CVE-2026-41874 | UNKNOWN | — | Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with access to the server file system to retrieve authentication details, … | Jul 28, 2026 |
| CVE-2026-18047 | MEDIUM | 6.5 | A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending … | Jul 28, 2026 |
| CVE-2026-18038 | MEDIUM | 4.3 | A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function ExecTool.Execute of the file goclaw/internal/http/tools_invoke.go of the … | Jul 28, 2026 |
| CVE-2026-15393 | MEDIUM | 6.4 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored … | Jul 28, 2026 |
| CVE-2026-15016 | MEDIUM | 6.4 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Readonly User Field … | Jul 28, 2026 |
| CVE-2026-4648 | UNKNOWN | — | Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tecnológicos S.L.U. (version used at Resurrection Fest 2025), … | Jul 28, 2026 |
| CVE-2026-21047 | UNKNOWN | — | Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code. | Jul 28, 2026 |
| CVE-2026-16774 | MEDIUM | 5.3 | The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handler. This is due … | Jul 28, 2026 |
| CVE-2026-16773 | MEDIUM | 5.3 | The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up … | Jul 28, 2026 |