Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26379
Total
1954
Critical
7969
High
8218
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-47760 | HIGH | 8.7 | TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling … | May 28, 2026 |
| CVE-2026-47759 | HIGH | 8.7 | TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, … | May 28, 2026 |
| CVE-2026-45017 | UNKNOWN | — | Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.0, the built-in FileSystemLoader and CachingFileSystemLoader do not guard against reading files … | May 28, 2026 |
| CVE-2026-44672 | UNKNOWN | — | mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3, the attacker can execute … | May 28, 2026 |
| CVE-2026-44594 | HIGH | 7.5 | esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI) vulnerability exists in the esbuild … | May 28, 2026 |
| CVE-2026-44593 | UNKNOWN | — | esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the legacy router first retrieves a response from legacyServer, parses … | May 28, 2026 |
| CVE-2026-44358 | HIGH | 8.2 | Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior to 1.0.1, the action's entrypoint.sh invoked DangerJS from … | May 28, 2026 |
| CVE-2026-41565 | UNKNOWN | — | CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers. The gcm_decrypt_verify, ccm_decrypt_verify, chacha20poly1305_decrypt_verify and eax_decrypt_verify XS routines copied … | May 28, 2026 |
| CVE-2026-35676 | HIGH | 8.2 | phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token … | May 28, 2026 |
| CVE-2026-35675 | HIGH | 8.2 | phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token … | May 28, 2026 |
| CVE-2026-35672 | HIGH | 7.5 | phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in API v4.0 where the default empty api.apiClientToken allows unauthenticated users to create and modify FAQ entries. … | May 28, 2026 |
| CVE-2026-35671 | HIGH | 8.8 | phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any user's … | May 28, 2026 |
| CVE-2026-9828 | UNKNOWN | — | Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted. More precisely, an attacker able to … | May 28, 2026 |
| CVE-2026-8990 | UNKNOWN | — | A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant himself full access to the device owner's … | May 28, 2026 |
| CVE-2026-8980 | UNKNOWN | — | The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-privileged user can change the passwords of the admin (operator) … | May 28, 2026 |
| CVE-2026-8979 | UNKNOWN | — | The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated remote attacker can change the password of the user … | May 28, 2026 |
| CVE-2026-49238 | HIGH | 8.4 | An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains … | May 28, 2026 |
| CVE-2026-49237 | HIGH | 7.8 | An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version 1.16.0 … | May 28, 2026 |
| CVE-2026-42250 | UNKNOWN | — | bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, … | May 28, 2026 |
| CVE-2026-37579 | UNKNOWN | — | An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMessageCodec.java component | May 28, 2026 |
| CVE-2026-37266 | HIGH | 8.0 | An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component | May 28, 2026 |
| CVE-2026-9818 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | May 28, 2026 |
| CVE-2026-9658 | UNKNOWN | — | Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths. The header injection rule was ineffective at blocking header injections in … | May 28, 2026 |
| CVE-2026-40914 | UNKNOWN | — | A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with security credentials that grant either the consume or send permission on … | May 28, 2026 |
| CVE-2026-9813 | UNKNOWN | — | FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/case/task.py. An attacker who can … | May 28, 2026 |