Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

29528
Total
2302
Critical
8845
High
9186
Medium
CVE ID Severity Score Description Published
CVE-2026-28214 UNKNOWN Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the ClumpletReader::getClumpletSize() function can overflow the totalLength value when … Apr 17, 2026
CVE-2026-28212 HIGH 7.5 Firebird is an open-source relational database management system. In versions prior to 6.0.0, 5.0.4, 4.0.7 and 3.0.14, when processing an op_slice network packet, the server … Apr 17, 2026
CVE-2026-27890 HIGH 8.2 Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when processing CNCT_specific_data segments during authentication, the server assumes … Apr 17, 2026
CVE-2026-5718 HIGH 8.1 The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and … Apr 17, 2026
CVE-2026-5710 HIGH 7.5 The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary File Read in … Apr 17, 2026
CVE-2026-40320 UNKNOWN Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the ConformityCheck class rendered the rule parameter through Jinja2's default Template() … Apr 17, 2026
CVE-2026-40319 UNKNOWN Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the RegexMatching check passes a user-supplied regular expression pattern directly to … Apr 17, 2026
CVE-2025-65104 HIGH 7.9 Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQLDA fields when communicating … Apr 17, 2026
CVE-2026-40518 HIGH 7.1 ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation where the agent name validation is bypassed. … Apr 17, 2026
CVE-2026-40516 HIGH 8.3 OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search tools that allows attackers to access private and localhost HTTP … Apr 17, 2026
CVE-2026-40515 HIGH 7.5 OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive files by exploiting incomplete path normalization in the permission checker. … Apr 17, 2026
CVE-2026-3464 HIGH 8.8 The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation in the 'ajax_attach_file' function … Apr 17, 2026
CVE-2026-21733 HIGH 7.3 Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory and files. … Apr 17, 2026
CVE-2026-6497 MEDIUM 6.3 A vulnerability was determined in prasathmani TinyFileManager up to 2.6. Affected by this vulnerability is an unknown functionality of the file /filemanager.php?p= ajax=true&type=upload of the … Apr 17, 2026
CVE-2026-6284 CRITICAL 9.1 An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited … Apr 17, 2026
CVE-2026-21709 UNKNOWN A vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement. Apr 17, 2026
CVE-2026-6496 MEDIUM 5.4 A vulnerability was found in prasathmani TinyFileManager up to 2.6. Affected is an unknown function of the file /filemanager.php of the component POST Parameter Handler. … Apr 17, 2026
CVE-2026-6493 LOW 3.5 A flaw has been found in lukevella rallly up to 4.7.4. This affects an unknown function of the file apps/web/src/app/[locale]/(auth)/reset-password/components/reset-password-form.tsx of the component Reset Password … Apr 17, 2026
CVE-2026-41153 MEDIUM 5.8 In JetBrains Junie before 252.549.29 command execution was possible via malicious project file Apr 17, 2026
CVE-2026-37749 CRITICAL 9.8 A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php. Apr 17, 2026
CVE-2026-6492 MEDIUM 5.3 A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea. The impacted element is an unknown function of the file /api/health/detailed of … Apr 17, 2026
CVE-2026-6491 MEDIUM 5.3 A security vulnerability has been detected in libvips up to 8.18.2. The affected element is the function im_minpos_vec of the file libvips/deprecated/vips7compat.c of the component … Apr 17, 2026
CVE-2026-6490 HIGH 7.3 A weakness has been identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. Impacted is an unknown function of the file admin/deletecourse.php of the component GET Request … Apr 17, 2026
CVE-2026-40459 UNKNOWN PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP syntax into ID-based search parameters, potentially resulting in … Apr 17, 2026
CVE-2026-40458 UNKNOWN PAC4J is vulnerable to Cross-Site Request Forgery (CSRF). A malicious attacker can craft a specially designed website which, when visited by a user, will automatically … Apr 17, 2026