Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

25592
Total
1903
Critical
7807
High
8024
Medium
CVE ID Severity Score Description Published
CVE-2026-44518 MEDIUM 5.3 liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS … May 29, 2026
CVE-2026-42951 MEDIUM 5.4 An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes. May 29, 2026
CVE-2026-42941 HIGH 8.3 The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change. May 29, 2026
CVE-2026-42929 HIGH 8.3 Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials. May 29, 2026
CVE-2026-40425 MEDIUM 5.7 The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password. May 29, 2026
CVE-2026-7786 CRITICAL 9.8 Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credentials embedded in the firmware image. These credentials can … May 29, 2026
CVE-2026-6824 HIGH 8.4 A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers … May 29, 2026
CVE-2026-5768 HIGH 8.8 The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range … May 29, 2026
CVE-2026-5386 CRITICAL 9.1 The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password … May 29, 2026
CVE-2026-47179 HIGH 7.7 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns the contents of any Docker Compose include directive … May 29, 2026
CVE-2026-47125 HIGH 8.8 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/environments/{id}/templates/variables endpoint, which writes the system-wide .env.global file … May 29, 2026
CVE-2026-45668 UNKNOWN Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malicious ZIP archive imported with … May 29, 2026
CVE-2026-45661 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows … May 29, 2026
CVE-2026-45660 MEDIUM 5.4 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image proxy's URL validation could be bypassed … May 29, 2026
CVE-2026-45633 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. … May 29, 2026
CVE-2026-45632 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, … May 29, 2026
CVE-2026-45631 CRITICAL 10.0 Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-secret-123456789") lets an unauthenticated attacker forge … May 29, 2026
CVE-2026-45630 CRITICAL 9.0 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner … May 29, 2026
CVE-2026-45629 CRITICAL 9.9 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any … May 29, 2026
CVE-2026-45628 CRITICAL 9.6 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template literals and executes them … May 29, 2026
CVE-2026-45627 HIGH 8.2 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query … May 29, 2026
CVE-2026-45626 MEDIUM 6.3 Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /environments/{id}/volumes/{volumeName}/browse accepts a path query parameter that is … May 29, 2026
CVE-2026-45625 CRITICAL 9.9 Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and … May 29, 2026
CVE-2026-45577 UNKNOWN Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app … May 29, 2026
CVE-2026-44697 HIGH 8.6 Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any peer that … May 29, 2026