Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26395
Total
1955
Critical
7973
High
8225
Medium
CVE ID Severity Score Description Published
CVE-2026-44502 MEDIUM 4.3 Bugsink is a self-hosted error tracking tool. Prior to 2.1.3, Bugsink’s webhook URL validation could be (partially) bypassed because of a mismatch in URL parsing. … May 26, 2026
CVE-2026-44314 MEDIUM 4.3 Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device only through Condition.Permission(User.class, getUserId(), Device.class) and then immediately streams … May 26, 2026
CVE-2026-43982 UNKNOWN Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploadedFileSaveIn() in lua/upload/upload.go uses filepath.Join() with the caller-supplied directory but performs no boundary check … May 26, 2026
CVE-2026-43981 UNKNOWN Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engine/luahandler.go, the sync.RWMutex protecting LoadCommonFunctions is released before L.Push() and L.PCall() execute. Since … May 26, 2026
CVE-2026-40384 UNKNOWN An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability. May 26, 2026
CVE-2026-40383 CRITICAL 9.8 An improper validation of user-supplied input leads to a local file inclusion vulnerability. May 26, 2026
CVE-2026-35223 UNKNOWN An improper access check allows unauthorized access to com_config webservice endpoints. May 26, 2026
CVE-2026-35222 CRITICAL 9.8 Improperly validated order clauses lead to a SQL injection vulnerability in com_tags. May 26, 2026
CVE-2026-35221 CRITICAL 9.8 Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder. May 26, 2026
CVE-2026-35220 MEDIUM 4.3 Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users. May 26, 2026
CVE-2026-30895 MEDIUM 6.1 Lack of output escaping leads to a XSS vector in the readmore links for com_content. May 26, 2026
CVE-2026-30894 MEDIUM 6.1 Lack of output escaping leads to a XSS vector in the content history component. May 26, 2026
CVE-2026-2264 UNKNOWN A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens. For … May 26, 2026
CVE-2026-25901 MEDIUM 6.1 Lack of output escaping leads to a XSS vector in the multilingual associations component. May 26, 2026
CVE-2026-25900 MEDIUM 6.1 Lack of output escaping leads to a XSS vector in the feed modules. May 26, 2026
CVE-2026-24212 HIGH 7.5 NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to … May 26, 2026
CVE-2026-24162 HIGH 7.8 NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead … May 26, 2026
CVE-2025-36221 MEDIUM 5.3 IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from … May 26, 2026
CVE-2025-36220 MEDIUM 4.3 IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A … May 26, 2026
CVE-2025-36148 MEDIUM 5.4 IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerable to cross-site scripting. This vulnerability allows … May 26, 2026
CVE-2025-36145 MEDIUM 5.4 IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files … May 26, 2026
CVE-2025-36126 MEDIUM 6.4 IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. … May 26, 2026
CVE-2025-14290 MEDIUM 5.4 IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vulnerable to server-side request forgery (SSRF). This may allow … May 26, 2026
CVE-2025-13755 MEDIUM 5.5 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files … May 26, 2026
CVE-2026-48692 HIGH 8.1 FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with grpc::InsecureServerCredentials() (src/fastnetmon.cpp line … May 26, 2026