Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51181
Total
4084
Critical
15175
High
14817
Medium
CVE ID Severity Score Description Published
CVE-2026-65879 UNKNOWN — Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers … Jul 27, 2026
CVE-2026-65878 UNKNOWN — Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file … Jul 27, 2026
CVE-2026-65877 UNKNOWN — Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search … Jul 27, 2026
CVE-2026-65876 UNKNOWN — Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of catid parameters in the loadMoreArticles endpoint leads … Jul 27, 2026
CVE-2026-65766 UNKNOWN — Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of order parameters in the Dynamic Content endpoint … Jul 27, 2026
CVE-2026-61511 CRITICAL 9.8 vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote … Jul 27, 2026
CVE-2026-17514 MEDIUM 5.3 A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Extract of the file lib/extract.js. This manipulation causes … Jul 27, 2026
CVE-2026-17513 LOW 3.3 A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected is the function ggml_ftype_to_ggml_type of the file ggml/src/ggml.c. The manipulation of the argument ftype results in … Jul 27, 2026
CVE-2026-15003 MEDIUM 5.6 A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted … Jul 27, 2026
CVE-2026-59690 HIGH 8.0 A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with … Jul 27, 2026
CVE-2026-59689 HIGH 8.0 An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges … Jul 27, 2026
CVE-2026-59688 HIGH 8.4 An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high … Jul 27, 2026
CVE-2026-59687 HIGH 8.4 An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high … Jul 27, 2026
CVE-2026-59686 HIGH 8.4 An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high … Jul 27, 2026
CVE-2026-56538 LOW 3.5 An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users. Jul 27, 2026
CVE-2026-56537 LOW 3.5 HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling … Jul 27, 2026
CVE-2026-17512 LOW 3.3 A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function log_mel_spectrogram of the file src/whisper.cpp. The manipulation leads to out-of-bounds read. The … Jul 27, 2026
CVE-2026-12991 UNKNOWN — The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to … Jul 27, 2026
CVE-2026-12990 UNKNOWN — An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client … Jul 27, 2026
CVE-2026-12989 UNKNOWN — A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal … Jul 27, 2026
CVE-2026-66053 MEDIUM 5.9 Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade … Jul 27, 2026
CVE-2026-58662 CRITICAL 9.1 Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended … Jul 27, 2026
CVE-2026-58389 HIGH 7.5 Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade … Jul 27, 2026
CVE-2026-58023 CRITICAL 9.1 Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes … Jul 27, 2026
CVE-2026-57917 UNKNOWN — proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's … Jul 27, 2026