Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26395
Total
1955
Critical
7973
High
8225
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-24638 | MEDIUM | 4.3 | Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 4.1121. | May 26, 2026 |
| CVE-2026-24590 | MEDIUM | 5.3 | Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Paid Videochat Turnkey Site: from … | May 26, 2026 |
| CVE-2026-8047 | HIGH | 7.5 | The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited out-of-bounds write. An unauthenticated remote attacker can exploit this … | May 26, 2026 |
| CVE-2026-8046 | HIGH | 8.1 | The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including those … | May 26, 2026 |
| CVE-2026-44469 | HIGH | 7.8 | The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU … | May 26, 2026 |
| CVE-2026-44468 | HIGH | 7.8 | The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining … | May 26, 2026 |
| CVE-2026-39655 | MEDIUM | 5.3 | Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mayosis Core: from n/a through 5.4.7. | May 26, 2026 |
| CVE-2026-9534 | MEDIUM | 6.3 | A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executing a … | May 26, 2026 |
| CVE-2026-9533 | MEDIUM | 6.3 | A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Performing … | May 26, 2026 |
| CVE-2026-9532 | MEDIUM | 6.3 | A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting … | May 26, 2026 |
| CVE-2026-9496 | HIGH | 7.5 | Versions of the package pacote from 11.2.7 are vulnerable to Denial of Service (DoS) via the addGitSha function. An attacker can exploit this vulnerability by … | May 26, 2026 |
| CVE-2026-9495 | HIGH | 7.3 | Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control Bypass due to the middleware being silently dropped from the … | May 26, 2026 |
| CVE-2026-3314 | MEDIUM | 4.6 | Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe modules), Hitachi Ops Center … | May 26, 2026 |
| CVE-2026-9531 | MEDIUM | 6.3 | A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. This manipulation … | May 26, 2026 |
| CVE-2026-9530 | LOW | 3.3 | A weakness has been identified in GNU LibreDWG up to 0.14. The impacted element is the function read_2004_compressed_section of the file src/decode.c of the component … | May 26, 2026 |
| CVE-2026-9529 | LOW | 3.3 | A security flaw has been discovered in GNU LibreDWG up to 0.14. The affected element is the function match_BLOCK_HEADER of the file dwggrep.c of the … | May 26, 2026 |
| CVE-2026-9528 | HIGH | 7.3 | A vulnerability was identified in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the file /admin/delete_judge.php. Such manipulation of the argument judge_id … | May 26, 2026 |
| CVE-2026-9527 | MEDIUM | 4.3 | A vulnerability was determined in itsourcecode Electronic Judging System 1.0. This issue affects some unknown processing of the file /admin/judges.php. This manipulation of the argument … | May 26, 2026 |
| CVE-2026-9526 | HIGH | 7.3 | A vulnerability was found in itsourcecode Electronic Judging System 1.0. This vulnerability affects unknown code of the file /admin/edit_team.php. The manipulation of the argument num_id … | May 26, 2026 |
| CVE-2026-9525 | HIGH | 7.3 | A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /admin/edit_judge.php. The manipulation of the argument … | May 26, 2026 |
| CVE-2026-9524 | MEDIUM | 6.3 | A flaw has been found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is the function execute of the component REST Endpoint. Executing … | May 26, 2026 |
| CVE-2026-9523 | HIGH | 7.3 | A vulnerability was detected in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 3000WEBV2. Affected by this vulnerability is an unknown functionality of … | May 26, 2026 |
| CVE-2026-9538 | UNKNOWN | — | Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->read($$data, … | May 26, 2026 |
| CVE-2026-9521 | HIGH | 7.3 | A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState in the library include/bitsery/ext/std_smart_ptr.h. Such manipulation leads to … | May 26, 2026 |
| CVE-2026-9520 | MEDIUM | 4.3 | A weakness has been identified in blitz-js blitz up to 3.0.2 on GitHub. This impacts an unknown function of the file packages/generator/templates/app/src/app/auth/components/LoginForm.tsx of the component … | May 26, 2026 |