Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

11202
Total
755
Critical
3234
High
3640
Medium
CVE ID Severity Score Description Published
CVE-2026-33774 MEDIUM 6.5 An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX Series allows an … Apr 09, 2026
CVE-2026-33773 MEDIUM 5.8 An Incorrect Initialization of Resource vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series and QFX Series device … Apr 09, 2026
CVE-2026-33771 HIGH 7.4 A Weak Password Requirements vulnerability in the password management function of Juniper Networks CTP OS might allow an unauthenticated, network-based attacker to exploit weak passwords … Apr 09, 2026
CVE-2026-21919 MEDIUM 6.5 An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker with low privileges … Apr 09, 2026
CVE-2026-21916 HIGH 7.3 A UNIX Symbolic Link (Symlink) Following vulnerability in the CLI of Juniper Networks Junos OS allows a local, authenticated attacker with low privileges to escalate … Apr 09, 2026
CVE-2026-21915 MEDIUM 6.7 A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows a local, high privileged … Apr 09, 2026
CVE-2026-21904 MEDIUM 6.1 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in … Apr 09, 2026
CVE-2025-59969 MEDIUM 6.5 A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the advanced forwarding toolkit (evo-aftmand/evo-pfemand) of Juniper Networks Junos OS Evolved on … Apr 09, 2026
CVE-2025-13914 HIGH 8.7 A Key Exchange without Entity Authentication vulnerability in the SSH implementation of Juniper Networks Apstra allows a unauthenticated, MITM attacker to impersonate managed devices. Due … Apr 09, 2026
CVE-2026-5980 HIGH 8.8 A flaw has been found in D-Link DIR-605L 2.13B01. Affected by this issue is the function formSetMACFilter of the file /goform/formSetMACFilter of the component POST … Apr 09, 2026
CVE-2026-5979 HIGH 8.8 A vulnerability was detected in D-Link DIR-605L 2.13B01. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ of the component POST Request … Apr 09, 2026
CVE-2026-5978 CRITICAL 9.8 A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The … Apr 09, 2026
CVE-2026-5977 CRITICAL 9.8 A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a … Apr 09, 2026
CVE-2026-5447 UNKNOWN Heap buffer overflow in CertFromX509 via AuthorityKeyIdentifier size confusion. A heap buffer overflow occurs when converting an X.509 certificate internally due to incorrect size handling … Apr 09, 2026
CVE-2026-5446 UNKNOWN In wolfSSL, ARIA-GCM cipher suites used in TLS 1.2 and DTLS 1.2 reuse an identical 12-byte GCM nonce for every application-data record. Because wc_AriaEncrypt is … Apr 09, 2026
CVE-2026-40109 LOW 3.1 Flux notification-controller is the event forwarder and notification dispatcher for the GitOps Toolkit controllers. Prior to 1.8.3, the gcr Receiver type in Flux notification-controller does … Apr 09, 2026
CVE-2026-40107 UNKNOWN SiYuan is a personal knowledge management system. Prior to 3.6.4, SiYuan configures Mermaid.js with securityLevel: "loose" and htmlLabels: true. In this mode, <img> tags with … Apr 09, 2026
CVE-2026-40093 HIGH 8.1 nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In 1.3.0 and earlier, block timestamp validation enforces that timestamp >= parent.timestamp for non-skip blocks and … Apr 09, 2026
CVE-2026-35206 UNKNOWN Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart will cause helm pull --untar [chart … Apr 09, 2026
CVE-2023-54364 MEDIUM 6.1 Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter … Apr 09, 2026
CVE-2023-54363 MEDIUM 6.1 Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating multiple GET parameters including show, reviews, … Apr 09, 2026
CVE-2023-54362 MEDIUM 6.1 Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the keyword parameter. Attackers can craft … Apr 09, 2026
CVE-2023-54361 MEDIUM 6.1 Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the filter_keyword parameter. Attackers can … Apr 09, 2026
CVE-2023-54360 MEDIUM 6.1 Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the review_id URL parameter. Attackers can … Apr 09, 2026
CVE-2023-54359 HIGH 8.2 WordPress adivaha Travel Plugin 2.3 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through … Apr 09, 2026