Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

10692
Total
727
Critical
3080
High
3407
Medium
CVE ID Severity Score Description Published
CVE-2026-7394 MEDIUM 4.7 A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/view_order.php of the component … Apr 29, 2026
CVE-2026-5712 HIGH 8.0 This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the … Apr 29, 2026
CVE-2026-26204 MEDIUM 4.4 Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 1.0.0 to before version 4.14.4, a heap-based out-of-bounds … Apr 29, 2026
CVE-2026-26015 UNKNOWN DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT website or any local … Apr 29, 2026
CVE-2026-7393 MEDIUM 4.7 A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file /admin/admin_class_novo.php of the component File Extension Handler. … Apr 29, 2026
CVE-2026-7392 MEDIUM 6.3 A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function delete_supplier of the file /ajax.php?action=delete_supplier. Such manipulation of … Apr 29, 2026
CVE-2026-7391 MEDIUM 6.3 A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function save_supplier of the file /ajax.php?action=save_supplier. This manipulation of … Apr 29, 2026
CVE-2026-6915 MEDIUM 6.3 An authorization flaw in the user management command could allow an authenticated user to make limited changes to authentication-related data associated with another user account. … Apr 29, 2026
CVE-2026-6914 MEDIUM 6.5 Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoDB server. This issue affects all MongoDB … Apr 29, 2026
CVE-2026-0206 MEDIUM 4.9 A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall. Apr 29, 2026
CVE-2026-0205 MEDIUM 6.8 A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services. Apr 29, 2026
CVE-2026-0204 HIGH 8.0 A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions. Apr 29, 2026
CVE-2026-7390 LOW 3.5 A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. The impacted element is the function Customer of the file /index.php?page=customer. The manipulation … Apr 29, 2026
CVE-2026-7389 HIGH 7.3 A security vulnerability has been detected in EyouCMS up to 1.7.9. The affected element is the function GetSortData of the file application/common.php. The manipulation of … Apr 29, 2026
CVE-2026-7388 MEDIUM 4.7 A weakness has been identified in EyouCMS up to 1.7.9. Impacted is the function editFile of the file application/admin/logic/FilemanagerLogic.php of the component Template File Handler. … Apr 29, 2026
CVE-2026-7386 HIGH 7.3 A flaw has been found in fatbobman mail-mcp-bridge up to 1.3.3. Affected is an unknown function of the file src/mail_mcp_server.py. Executing a manipulation of the … Apr 29, 2026
CVE-2026-6849 HIGH 8.8 Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus OS My Computer … Apr 29, 2026
CVE-2026-5166 CRITICAL 9.6 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center allows Path Traversal. … Apr 29, 2026
CVE-2026-42198 HIGH 7.5 pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during … Apr 29, 2026
CVE-2026-41940 CRITICAL 9.8 cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to … Apr 29, 2026
CVE-2026-40230 UNKNOWN Helpy contains a stored cross-site scripting vulnerability in the knowledge base Doc rendering logic. An authenticated attacker with admin or agent editor privileges can persist … Apr 29, 2026
CVE-2026-40229 UNKNOWN Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can persist arbitrary HTML in their account name field … Apr 29, 2026
CVE-2026-38993 MEDIUM 6.5 Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows authenticated attackers to write files to arbitrary locations within … Apr 29, 2026
CVE-2026-38991 HIGH 8.8 Cockpit 2.13.5 and earlier is affected by a misconfiguration within the Bucket component _isFileTypeAllowed function where a specially crafted filename bypasses an extension filter. This … Apr 29, 2026
CVE-2026-37555 HIGH 7.5 An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code … Apr 29, 2026