Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25592
Total
1903
Critical
7807
High
8024
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2018-25383 | HIGH | 8.4 | Free MP3 CD Ripper 2.8 contains a stack-based buffer overflow vulnerability in WMA file processing that allows local attackers to bypass DEP protection via structured … | May 29, 2026 |
| CVE-2018-25382 | HIGH | 8.2 | Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the uname parameter. Attackers can … | May 29, 2026 |
| CVE-2026-4290 | CRITICAL | 9.1 | The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and … | May 29, 2026 |
| CVE-2026-45609 | HIGH | 7.2 | mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mcp-security framework fails to implement the mandatory SSRF … | May 29, 2026 |
| CVE-2026-41159 | UNKNOWN | — | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, Mermaid's default configuration allows … | May 29, 2026 |
| CVE-2026-41150 | UNKNOWN | — | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service … | May 29, 2026 |
| CVE-2026-39292 | UNKNOWN | — | Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder module that allows remote attackers to upload arbitrary files and achieve remote … | May 29, 2026 |
| CVE-2026-10063 | HIGH | 8.8 | A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipulation of the argument … | May 29, 2026 |
| CVE-2026-10062 | HIGH | 8.8 | A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSetRoute. This manipulation of the argument … | May 29, 2026 |
| CVE-2026-10042 | CRITICAL | 9.8 | manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deserialization of untrusted pickle data in the share.py module, … | May 29, 2026 |
| CVE-2026-49325 | MEDIUM | 4.6 | Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows a physical attacker with … | May 29, 2026 |
| CVE-2026-49318 | LOW | 2.4 | Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker … | May 29, 2026 |
| CVE-2026-49317 | LOW | 2.4 | Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker … | May 29, 2026 |
| CVE-2026-49316 | MEDIUM | 4.6 | Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the … | May 29, 2026 |
| CVE-2026-47696 | UNKNOWN | — | WWBN AVideo is an open source video platform. In 29.0 and earlier, plugin/AuthorizeNet/processPayment.json.php credits the logged-in user's wallet based only on the attacker-controlled amount POST … | May 29, 2026 |
| CVE-2026-47694 | MEDIUM | 5.4 | WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input and later renders category_description as raw … | May 29, 2026 |
| CVE-2026-46510 | HIGH | 8.2 | form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys (e.g. name[sub]) into nested objects without filtering __proto__, constructor, or prototype. A … | May 29, 2026 |
| CVE-2026-46376 | UNKNOWN | — | FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel … | May 29, 2026 |
| CVE-2026-46337 | UNKNOWN | — | WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary image files anywhere on disk that … | May 29, 2026 |
| CVE-2026-45731 | UNKNOWN | — | WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['updateFile'] as a relative path under updatedb/ and passes it to … | May 29, 2026 |
| CVE-2026-45707 | HIGH | 8.1 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.2, when ENABLE_MULTI_TENANT=true, the HTTP transport … | May 29, 2026 |
| CVE-2026-45620 | MEDIUM | 5.3 | WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an entry guard: … | May 29, 2026 |
| CVE-2026-45619 | MEDIUM | 6.5 | WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use the $resolvedIP out-param of isSSRFSafeURL() … | May 29, 2026 |
| CVE-2026-45615 | HIGH | 8.2 | mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decoding skeleton files generated by asn1c (specifically … | May 29, 2026 |
| CVE-2026-45610 | MEDIUM | 5.7 | WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/LoginControl/set.json.php accepts … | May 29, 2026 |