Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

25534
Total
1899
Critical
7798
High
8005
Medium
CVE ID Severity Score Description Published
CVE-2026-49369 MEDIUM 4.3 In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages May 29, 2026
CVE-2026-49368 HIGH 8.7 In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible May 29, 2026
CVE-2026-49367 HIGH 8.0 In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account May 29, 2026
CVE-2026-49366 HIGH 7.8 In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion May 29, 2026
CVE-2026-47745 MEDIUM 6.5 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and per-record actions (enable, … May 29, 2026
CVE-2026-47744 CRITICAL 9.9 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take … May 29, 2026
CVE-2026-47742 MEDIUM 6.5 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping, Files) had no … May 29, 2026
CVE-2026-47741 MEDIUM 5.9 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the Order row before checking and incrementing the discount's total_use counter. Under … May 29, 2026
CVE-2026-47740 HIGH 8.1 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by … May 29, 2026
CVE-2026-46372 HIGH 8.5 SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. … May 29, 2026
CVE-2026-46344 MEDIUM 5.3 liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS … May 29, 2026
CVE-2026-44652 UNKNOWN SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. … May 29, 2026
CVE-2026-44651 UNKNOWN SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. … May 29, 2026
CVE-2026-44650 CRITICAL 9.1 SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. … May 29, 2026
CVE-2026-44649 CRITICAL 9.8 SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. … May 29, 2026
CVE-2026-44648 HIGH 7.5 SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. … May 29, 2026
CVE-2026-44611 MEDIUM 5.4 Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks. May 29, 2026
CVE-2026-44518 MEDIUM 5.3 liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS … May 29, 2026
CVE-2026-42951 MEDIUM 5.4 An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes. May 29, 2026
CVE-2026-42941 HIGH 8.3 The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change. May 29, 2026
CVE-2026-42929 HIGH 8.3 Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials. May 29, 2026
CVE-2026-40425 MEDIUM 5.7 The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password. May 29, 2026
CVE-2026-7786 CRITICAL 9.8 Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credentials embedded in the firmware image. These credentials can … May 29, 2026
CVE-2026-6824 HIGH 8.4 A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers … May 29, 2026
CVE-2026-5768 HIGH 8.8 The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range … May 29, 2026