Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26391
Total
1955
Critical
7971
High
8223
Medium
CVE ID Severity Score Description Published
CVE-2026-7452 HIGH 7.8 A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to … May 26, 2026
CVE-2026-7451 HIGH 7.8 A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to … May 26, 2026
CVE-2026-7450 MEDIUM 5.3 A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to … May 26, 2026
CVE-2026-7251 CRITICAL 9.8 Eppendorf BioFlo 320 is vulnerable to due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo … May 26, 2026
CVE-2026-48696 MEDIUM 6.2 FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different vulnerability than CVE-2026-48686 and CVE-2026-48689. May 26, 2026
CVE-2026-48695 HIGH 8.1 FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php (lines 107-108) constructs … May 26, 2026
CVE-2026-48694 HIGH 8.1 FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integration plugin. In src/juniper_plugin/fastnetmon_juniper.php, the $IP_ATTACK variable (received from argv[1]) is … May 26, 2026
CVE-2026-47202 UNKNOWN Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to request a … May 26, 2026
CVE-2026-46624 CRITICAL 9.9 Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL … May 26, 2026
CVE-2026-44776 UNKNOWN Kavita is a cross platform reading server. Prior to 0.9.0, the download, size-check, and chapter metadata endpoints do not enforce library-level authorization. A low-privileged user … May 26, 2026
CVE-2026-44775 UNKNOWN Kavita is a cross platform reading server. Prior to 0.9.0, the ReaderController.GetImage endpoint is decorated with [AllowAnonymous], allowing completely unauthenticated access to page images from … May 26, 2026
CVE-2026-44749 MEDIUM 4.3 The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI … May 26, 2026
CVE-2026-44730 HIGH 7.2 OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.7, an organization admin can escalate their privileges by … May 26, 2026
CVE-2026-44728 HIGH 8.2 Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted … May 26, 2026
CVE-2026-44707 MEDIUM 6.8 Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentication flow. Because email confirmation was … May 26, 2026
CVE-2026-44706 HIGH 8.5 Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection vulnerability exists in the conversation and contact filter APIs. When filtering … May 26, 2026
CVE-2026-44669 HIGH 8.7 FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in assessment … May 26, 2026
CVE-2026-44668 CRITICAL 9.8 FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invoke() without checking … May 26, 2026
CVE-2026-44667 HIGH 8.7 FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in remediation … May 26, 2026
CVE-2026-42448 LOW 3.5 Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. Prior to 0.24.0, there is a path traversal when … May 26, 2026
CVE-2026-41164 MEDIUM 4.4 nuts-node is the reference implementation of the Nuts specification. Prior to 6.2.3 and 5.4.31, the v1 access token introspection endpoint (/auth/v1/introspect_access_token) accepts any JWT signed … May 26, 2026
CVE-2026-24201 MEDIUM 5.8 NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause an out-of-bound access. A successful exploit of this vulnerability … May 26, 2026
CVE-2026-24200 HIGH 7.0 NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free for stack memory. A successful exploit of … May 26, 2026
CVE-2026-24199 MEDIUM 4.7 NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where a user could cause a race condition by reordering compiler or processor … May 26, 2026
CVE-2026-24198 MEDIUM 5.6 NVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memory, which might cause … May 26, 2026