Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

20346
Total
1466
Critical
6163
High
6464
Medium
CVE ID Severity Score Description Published
CVE-2026-53358 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() l2cap_chan_close() removes the channel from … Jul 02, 2026
CVE-2026-53357 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() bt_accept_dequeue() unlinks a not-yet-accepted child from the parent … Jul 02, 2026
CVE-2026-50748 CRITICAL 9.9 A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute … Jul 02, 2026
CVE-2026-50747 CRITICAL 9.9 A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application … Jul 02, 2026
CVE-2026-50746 CRITICAL 10.0 A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection … Jul 02, 2026
CVE-2026-12168 HIGH 7.8 An improper validation vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to escalate privileges to SYSTEM and execute arbitrary code in … Jul 02, 2026
CVE-2026-12167 HIGH 7.8 The Minifilter communication port for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to access privileged driver functionality via a communication interface that … Jul 02, 2026
CVE-2026-12166 MEDIUM 5.5 A NULL pointer dereference vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to cause a denial of service via crafted requests … Jul 02, 2026
CVE-2026-4767 CRITICAL 9.8 Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Authentication Abuse. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117. Jul 02, 2026
CVE-2026-5524 CRITICAL 9.8 The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including … Jul 02, 2026
CVE-2026-58653 MEDIUM 4.3 PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies belongs to the URL workspace. An attacker can create issues … Jul 02, 2026
CVE-2026-58652 HIGH 7.5 luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-app-travelmate write ACL is granted config-wide UCI write access to the … Jul 02, 2026
CVE-2026-4772 MEDIUM 5.4 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Stored XSS. This issue affects WAF-ASP: from … Jul 02, 2026
CVE-2026-4770 MEDIUM 4.6 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. Web Application Firewall allows DOM-Based XSS. This issue affects … Jul 02, 2026
CVE-2026-57766 HIGH 8.8 Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions. Jul 02, 2026
CVE-2026-57765 HIGH 8.5 Contributor SQL Injection in WP EasyCart <= 5.9.0 versions. Jul 02, 2026
CVE-2026-57764 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions. Jul 02, 2026
CVE-2026-57763 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions. Jul 02, 2026
CVE-2026-57762 MEDIUM 5.9 Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions. Jul 02, 2026
CVE-2026-57761 HIGH 7.1 Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions. Jul 02, 2026
CVE-2026-57760 MEDIUM 5.3 Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sendcloud Shipping: from n/a through 1.0.29. Jul 02, 2026
CVE-2026-57759 HIGH 8.8 Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions. Jul 02, 2026
CVE-2026-57758 HIGH 7.1 Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions. Jul 02, 2026
CVE-2026-57757 HIGH 7.1 Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions. Jul 02, 2026
CVE-2026-57756 HIGH 8.5 Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions. Jul 02, 2026