Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26401
Total
1955
Critical
7975
High
8228
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-3039 | HIGH | 7.5 | BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically … | May 20, 2026 |
| CVE-2026-29518 | HIGH | 7.0 | Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended … | May 20, 2026 |
| CVE-2026-27424 | MEDIUM | 4.3 | Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Image Photo … | May 20, 2026 |
| CVE-2026-27405 | MEDIUM | 6.5 | Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9. | May 20, 2026 |
| CVE-2026-24573 | MEDIUM | 6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualizer allows Stored XSS. This issue affects Visualizer: from n/a before 4.0.0. | May 20, 2026 |
| CVE-2025-11954 | HIGH | 8.0 | Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross Site Request Forgery. This issue affects WISECP: through 20022026. NOTE: … | May 20, 2026 |
| CVE-2025-31985 | LOW | 3.7 | HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform … | May 20, 2026 |
| CVE-2025-31973 | MEDIUM | 4.0 | HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce … | May 20, 2026 |
| CVE-2026-25602 | MEDIUM | 4.4 | Insufficient Verification of Data Authenticity vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component makes it possible to send messages to any email … | May 20, 2026 |
| CVE-2026-22315 | HIGH | 7.2 | Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables the export of user data, including cleartext passwords, via the … | May 20, 2026 |
| CVE-2026-22314 | CRITICAL | 9.0 | Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' … | May 20, 2026 |
| CVE-2026-0857 | MEDIUM | 6.0 | Cleartext Storage of Sensitive Information in Memory vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component. This issue affects Meona Client Launcher Component: … | May 20, 2026 |
| CVE-2026-0856 | HIGH | 7.8 | Improper Access Control vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables a normal user gaining access to the admin panel. This … | May 20, 2026 |
| CVE-2026-9064 | HIGH | 7.5 | A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per … | May 20, 2026 |
| CVE-2026-6728 | MEDIUM | 5.3 | The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.0.9 via the 'get_stream_data()' function. This makes … | May 20, 2026 |
| CVE-2026-44933 | HIGH | 7.8 | `PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) in standard configurations or when using `--root`. If … | May 20, 2026 |
| CVE-2026-44608 | MEDIUM | 5.9 | NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, … | May 20, 2026 |
| CVE-2026-44390 | MEDIUM | 5.3 | NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name … | May 20, 2026 |
| CVE-2026-42960 | CRITICAL | 10.0 | NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS … | May 20, 2026 |
| CVE-2026-42959 | HIGH | 7.5 | NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash … | May 20, 2026 |
| CVE-2026-42944 | HIGH | 7.5 | NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie … | May 20, 2026 |
| CVE-2026-42923 | MEDIUM | 5.3 | NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to consult the negative cache … | May 20, 2026 |
| CVE-2026-42534 | MEDIUM | 5.3 | NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. … | May 20, 2026 |
| CVE-2026-41292 | HIGH | 7.5 | NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS … | May 20, 2026 |
| CVE-2026-41054 | HIGH | 7.8 | In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/entropy/haveged`). However, while it detects if the connecting user is not … | May 20, 2026 |