Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26391
Total
1955
Critical
7971
High
8223
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-25444 | MEDIUM | 4.3 | Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9. | May 26, 2026 |
| CVE-2026-25426 | MEDIUM | 5.3 | Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Taxi Booking Manager … | May 26, 2026 |
| CVE-2026-24520 | MEDIUM | 4.3 | Missing Authorization vulnerability in bPlugins Tiktok Feed allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Tiktok Feed: from n/a through 1.0.24. | May 26, 2026 |
| CVE-2025-68710 | UNKNOWN | — | Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is … | May 26, 2026 |
| CVE-2025-68709 | UNKNOWN | — | SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript execution via BrowserMainActivity, which accepts VIEW intents with javascript: URIs. … | May 26, 2026 |
| CVE-2026-9572 | LOW | 3.3 | A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the function Media_GetSample of the file src/isomedia/media.c of the … | May 26, 2026 |
| CVE-2026-9568 | MEDIUM | 5.0 | A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file /api/v1/provision of the component … | May 26, 2026 |
| CVE-2026-8890 | HIGH | 8.2 | code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers to impersonate arbitrary users by supplying a crafted JSON payload in … | May 26, 2026 |
| CVE-2026-4051 | HIGH | 7.2 | IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to execute remote code due to exposed method that is … | May 26, 2026 |
| CVE-2026-48689 | CRITICAL | 9.8 | FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary_buffer.hpp). Five methods (append_dynamic_buffer, append_data_as_pointer, append_data_as_object_ptr, memcpy_from_ptr, memcpy_from_object_ptr) use an … | May 26, 2026 |
| CVE-2026-3660 | CRITICAL | 9.8 | IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain … | May 26, 2026 |
| CVE-2026-3603 | HIGH | 7.1 | IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through Interim Fix 021, 7.1.0 Interim Fix 001 through Interim Fix 009, and 7.2.0 and 7.2.0 Interim … | May 26, 2026 |
| CVE-2026-9567 | LOW | 3.3 | A security flaw has been discovered in GPAC up to 2.4.0. Affected is the function MergeFragment of the file src/isomedia/isom_intern.c of the component MP4Box. The … | May 26, 2026 |
| CVE-2026-9566 | MEDIUM | 4.3 | A vulnerability was identified in teableio teable up to 1.9.x. This impacts an unknown function of the file apps/nextjs-app/src/features/auth/pages/LoginPage.tsx of the component Sign-up. The manipulation … | May 26, 2026 |
| CVE-2026-9560 | UNKNOWN | — | Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC … | May 26, 2026 |
| CVE-2026-9170 | HIGH | 7.5 | IBM HTTP Server 8.5, and 9.0 | May 26, 2026 |
| CVE-2026-8856 | HIGH | 7.7 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server … | May 26, 2026 |
| CVE-2026-8855 | HIGH | 8.1 | IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication). | May 26, 2026 |
| CVE-2026-8854 | HIGH | 7.5 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache. | May 26, 2026 |
| CVE-2026-8835 | HIGH | 7.3 | IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to … | May 26, 2026 |
| CVE-2026-8834 | HIGH | 8.0 | IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to execute … | May 26, 2026 |
| CVE-2026-8633 | CRITICAL | 9.8 | IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to … | May 26, 2026 |
| CVE-2026-8620 | HIGH | 7.5 | IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to … | May 26, 2026 |
| CVE-2026-7454 | HIGH | 7.8 | A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to … | May 26, 2026 |
| CVE-2026-7453 | MEDIUM | 5.3 | A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion vulnerability, leading to a denial-of-service condition. | May 26, 2026 |