Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
29528
Total
2302
Critical
8845
High
9186
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-40341 | LOW | 3.5 | libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_unpack_EOS_FocusInfoEx could be used … | Apr 18, 2026 |
| CVE-2026-40340 | MEDIUM | 6.1 | libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read vulnerability in `ptp_unpack_OI()` in `camlibs/ptp2/ptp-pack.c` (lines 530–563). … | Apr 18, 2026 |
| CVE-2026-40339 | MEDIUM | 5.2 | libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (line 842). The … | Apr 18, 2026 |
| CVE-2026-40338 | MEDIUM | 5.2 | libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the PTP_DPFF_Enumeration case of `ptp_unpack_Sony_DPD()` in … | Apr 18, 2026 |
| CVE-2026-40337 | MEDIUM | 5.1 | The Sentry kernel is a high security level micro-kernel implementation made for high security embedded systems. A given task with one of the DEV or … | Apr 18, 2026 |
| CVE-2026-40336 | LOW | 2.4 | libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have a memory leak in `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (lines 884–885). When … | Apr 18, 2026 |
| CVE-2026-40335 | MEDIUM | 5.2 | libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `ptp_unpack_DPV()` in `camlibs/ptp2/ptp-pack.c` (lines 622–629). The … | Apr 18, 2026 |
| CVE-2026-40334 | LOW | 3.5 | libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, a missing null terminator exists in ptp_unpack_Canon_FE() in camlibs/ptp2/ptp-pack.c (line … | Apr 18, 2026 |
| CVE-2026-40333 | MEDIUM | 6.1 | libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, two functions in camlibs/ptp2/ptp-pack.c accept a data pointer but no … | Apr 18, 2026 |
| CVE-2026-40324 | CRITICAL | 9.1 | Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's recursive descent parser `Utf8GraphQLParser` has no recursion depth … | Apr 18, 2026 |
| CVE-2026-40323 | UNKNOWN | — | SP1 is a zero‑knowledge virtual machine that proves the correct execution of programs compiled for the RISC-V architecture. In versions 6.0.0 through 6.0.2, a soundness … | Apr 18, 2026 |
| CVE-2026-2262 | HIGH | 7.5 | The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.21 via the `/wp-json/wp/v2/eablocks/ea_appointments/` REST API … | Apr 18, 2026 |
| CVE-2026-5250 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Apr 17, 2026 |
| CVE-2026-40486 | MEDIUM | 4.3 | Kimai is an open-source time tracking application. In versions 2.52.0 and below, the User Preferences API endpoint (PATCH /api/users/{id}/preferences) applies submitted preference values without checking … | Apr 17, 2026 |
| CVE-2026-40481 | UNKNOWN | — | monetr is a budgeting application for recurring expenses. In versions 1.12.3 and below, the public Stripe webhook endpoint buffers the entire request body into memory … | Apr 17, 2026 |
| CVE-2026-40479 | MEDIUM | 5.4 | Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in KimaiEscape.js does not escape double quote or single quote … | Apr 17, 2026 |
| CVE-2026-2434 | MEDIUM | 6.4 | The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attributes in all versions up to, and including, 2.5.8.1 due … | Apr 17, 2026 |
| CVE-2026-5720 | UNKNOWN | — | miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending … | Apr 17, 2026 |
| CVE-2026-40478 | CRITICAL | 9.0 | Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression … | Apr 17, 2026 |
| CVE-2026-40477 | CRITICAL | 9.0 | Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution … | Apr 17, 2026 |
| CVE-2026-40476 | UNKNOWN | — | graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCanBeMerged validation rule performs O(n²) pairwise comparisons of fields sharing the same … | Apr 17, 2026 |
| CVE-2026-40474 | HIGH | 7.6 | wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares permission_required = 'config.change_gymconfig' but inherits WgerFormMixin instead of … | Apr 17, 2026 |
| CVE-2026-40353 | UNKNOWN | — | wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in AbstractLicenseModel constructs HTML by directly interpolating user-controlled … | Apr 17, 2026 |
| CVE-2026-40352 | HIGH | 8.8 | FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An authenticated attacker can … | Apr 17, 2026 |
| CVE-2026-40351 | CRITICAL | 9.8 | FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an … | Apr 17, 2026 |