Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

34320
Total
2676
Critical
10130
High
10349
Medium
CVE ID Severity Score Description Published
CVE-2026-18929 UNKNOWN Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processing .docx files. The library uses yazl for zip … Aug 18, 2026
CVE-2026-43971 UNKNOWN Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via unescaped special characters in cow_link:link/1. cow_link:do_link/1 in cowlib interpolates … Aug 18, 2026
CVE-2024-14045 MEDIUM 6.3 A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Product Supplier Edit … Aug 18, 2026
CVE-2026-34884 UNKNOWN SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade … Aug 18, 2026
CVE-2026-15371 HIGH 8.1 Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can … Aug 18, 2026
CVE-2026-75091 HIGH 7.2 The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, … Aug 18, 2026
CVE-2026-15748 CRITICAL 9.8 The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This … Aug 18, 2026
CVE-2026-75151 MEDIUM 4.3 A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads … Aug 18, 2026
CVE-2026-11801 HIGH 7.5 The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to … Aug 18, 2026
CVE-2026-75094 CRITICAL 9.1 A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component CGI Interface. This manipulation … Aug 18, 2026
CVE-2026-75093 MEDIUM 4.3 A security vulnerability has been detected in sonos tract up to 0.23.4. This impacts the function Tensor::from_raw_dt_align of the file data/src/tensor.rs of the component ONNX … Aug 18, 2026
CVE-2026-75090 MEDIUM 4.3 A vulnerability was detected in EricLBuehler Mistral.rs up to 0.8.22. Affected by this issue is the function convert_gguf_to_hf_tokenizer of the file mistralrs-core/src/gguf/gguf_tokenizer.rs of the component … Aug 18, 2026
CVE-2026-75089 HIGH 7.3 A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file user/check_availability.php. This manipulation … Aug 18, 2026
CVE-2026-75088 MEDIUM 6.3 A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewbilling.php. Executing a manipulation of the argument … Aug 18, 2026
CVE-2026-75087 MEDIUM 6.3 A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /viewdepartment.php. Performing a manipulation of the argument … Aug 18, 2026
CVE-2026-75086 MEDIUM 6.3 A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewroom.php. Such manipulation of … Aug 18, 2026
CVE-2026-75082 MEDIUM 4.3 A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component … Aug 18, 2026
CVE-2026-75081 MEDIUM 4.3 A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id … Aug 18, 2026
CVE-2026-75080 HIGH 7.3 A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the file /edit_subject1.php. The … Aug 18, 2026
CVE-2026-75079 HIGH 7.3 A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_subject2.php. Executing a manipulation … Aug 18, 2026
CVE-2026-9693 LOW 3.5 Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, … Aug 17, 2026
CVE-2026-75587 LOW 3.6 Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to … Aug 17, 2026
CVE-2026-75078 MEDIUM 4.3 A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSHRM1.php. Performing a … Aug 17, 2026
CVE-2026-67961 UNKNOWN An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke script execution. Aug 17, 2026
CVE-2026-67919 UNKNOWN An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components Aug 17, 2026