Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26379
Total
1954
Critical
7969
High
8218
Medium
CVE ID Severity Score Description Published
CVE-2026-47760 HIGH 8.7 TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling … May 28, 2026
CVE-2026-47759 HIGH 8.7 TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, … May 28, 2026
CVE-2026-45017 UNKNOWN Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.0, the built-in FileSystemLoader and CachingFileSystemLoader do not guard against reading files … May 28, 2026
CVE-2026-44672 UNKNOWN mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3, the attacker can execute … May 28, 2026
CVE-2026-44594 HIGH 7.5 esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI) vulnerability exists in the esbuild … May 28, 2026
CVE-2026-44593 UNKNOWN esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the legacy router first retrieves a response from legacyServer, parses … May 28, 2026
CVE-2026-44358 HIGH 8.2 Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior to 1.0.1, the action's entrypoint.sh invoked DangerJS from … May 28, 2026
CVE-2026-41565 UNKNOWN CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers. The gcm_decrypt_verify, ccm_decrypt_verify, chacha20poly1305_decrypt_verify and eax_decrypt_verify XS routines copied … May 28, 2026
CVE-2026-35676 HIGH 8.2 phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token … May 28, 2026
CVE-2026-35675 HIGH 8.2 phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token … May 28, 2026
CVE-2026-35672 HIGH 7.5 phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in API v4.0 where the default empty api.apiClientToken allows unauthenticated users to create and modify FAQ entries. … May 28, 2026
CVE-2026-35671 HIGH 8.8 phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any user's … May 28, 2026
CVE-2026-9828 UNKNOWN Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted. More precisely, an attacker able to … May 28, 2026
CVE-2026-8990 UNKNOWN A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant himself full access to the device owner's … May 28, 2026
CVE-2026-8980 UNKNOWN The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-privileged user can change the passwords of the admin (operator) … May 28, 2026
CVE-2026-8979 UNKNOWN The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated remote attacker can change the password of the user … May 28, 2026
CVE-2026-49238 HIGH 8.4 An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains … May 28, 2026
CVE-2026-49237 HIGH 7.8 An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version 1.16.0 … May 28, 2026
CVE-2026-42250 UNKNOWN bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, … May 28, 2026
CVE-2026-37579 UNKNOWN An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMessageCodec.java component May 28, 2026
CVE-2026-37266 HIGH 8.0 An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component May 28, 2026
CVE-2026-9818 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. May 28, 2026
CVE-2026-9658 UNKNOWN Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths. The header injection rule was ineffective at blocking header injections in … May 28, 2026
CVE-2026-40914 UNKNOWN A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with security credentials that grant either the consume or send permission on … May 28, 2026
CVE-2026-9813 UNKNOWN FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/case/task.py. An attacker who can … May 28, 2026