Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25534
Total
1899
Critical
7798
High
8005
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-49369 | MEDIUM | 4.3 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages | May 29, 2026 |
| CVE-2026-49368 | HIGH | 8.7 | In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible | May 29, 2026 |
| CVE-2026-49367 | HIGH | 8.0 | In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account | May 29, 2026 |
| CVE-2026-49366 | HIGH | 7.8 | In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion | May 29, 2026 |
| CVE-2026-47745 | MEDIUM | 6.5 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and per-record actions (enable, … | May 29, 2026 |
| CVE-2026-47744 | CRITICAL | 9.9 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take … | May 29, 2026 |
| CVE-2026-47742 | MEDIUM | 6.5 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping, Files) had no … | May 29, 2026 |
| CVE-2026-47741 | MEDIUM | 5.9 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the Order row before checking and incrementing the discount's total_use counter. Under … | May 29, 2026 |
| CVE-2026-47740 | HIGH | 8.1 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by … | May 29, 2026 |
| CVE-2026-46372 | HIGH | 8.5 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. … | May 29, 2026 |
| CVE-2026-46344 | MEDIUM | 5.3 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS … | May 29, 2026 |
| CVE-2026-44652 | UNKNOWN | — | SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. … | May 29, 2026 |
| CVE-2026-44651 | UNKNOWN | — | SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. … | May 29, 2026 |
| CVE-2026-44650 | CRITICAL | 9.1 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. … | May 29, 2026 |
| CVE-2026-44649 | CRITICAL | 9.8 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. … | May 29, 2026 |
| CVE-2026-44648 | HIGH | 7.5 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. … | May 29, 2026 |
| CVE-2026-44611 | MEDIUM | 5.4 | Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks. | May 29, 2026 |
| CVE-2026-44518 | MEDIUM | 5.3 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS … | May 29, 2026 |
| CVE-2026-42951 | MEDIUM | 5.4 | An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes. | May 29, 2026 |
| CVE-2026-42941 | HIGH | 8.3 | The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change. | May 29, 2026 |
| CVE-2026-42929 | HIGH | 8.3 | Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials. | May 29, 2026 |
| CVE-2026-40425 | MEDIUM | 5.7 | The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password. | May 29, 2026 |
| CVE-2026-7786 | CRITICAL | 9.8 | Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credentials embedded in the firmware image. These credentials can … | May 29, 2026 |
| CVE-2026-6824 | HIGH | 8.4 | A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers … | May 29, 2026 |
| CVE-2026-5768 | HIGH | 8.8 | The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range … | May 29, 2026 |