Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26848
Total
1978
Critical
8065
High
8299
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-7182 | UNKNOWN | — | Diagram's export module is vulnerable to Path Traversal in src attribute due to lack of HTML sanitization. An unauthenticated user could craft the html payload … | May 15, 2026 |
| CVE-2026-41553 | UNKNOWN | — | PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. An unauthenticated … | May 15, 2026 |
| CVE-2026-41552 | UNKNOWN | — | PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated user could … | May 15, 2026 |
| CVE-2026-8503 | MEDIUM | 6.5 | Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids. Apache::Session::Generate::SHA256 generated session ids insecurely. The default session id generator returns a SHA-256 hash of … | May 15, 2026 |
| CVE-2026-8454 | MEDIUM | 5.3 | Imager::File::GIF versions through 1.002 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row … | May 15, 2026 |
| CVE-2026-41971 | MEDIUM | 5.5 | Permission control vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | May 15, 2026 |
| CVE-2026-41970 | MEDIUM | 6.8 | Out-of-bounds write vulnerability in the distributed file system module. Impact: Successful exploitation of this vulnerability may affect availability. | May 15, 2026 |
| CVE-2026-41969 | MEDIUM | 6.2 | Permission control vulnerability in the projection module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | May 15, 2026 |
| CVE-2026-41968 | MEDIUM | 5.9 | Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability. | May 15, 2026 |
| CVE-2026-41967 | MEDIUM | 5.9 | Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability. | May 15, 2026 |
| CVE-2026-41966 | MEDIUM | 5.6 | Permission control vulnerability in the smart sensing service. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | May 15, 2026 |
| CVE-2026-41965 | MEDIUM | 5.6 | Use-After-Free (UAF) vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability. | May 15, 2026 |
| CVE-2026-41964 | HIGH | 8.4 | Permission control vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability. | May 15, 2026 |
| CVE-2026-41963 | LOW | 2.8 | Stack overflow vulnerability in the media platform. Impact: Successful exploitation of this vulnerability may affect availability. | May 15, 2026 |
| CVE-2026-41962 | LOW | 3.6 | Permission control vulnerability in the app management and control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | May 15, 2026 |
| CVE-2026-41961 | MEDIUM | 5.9 | Permission control vulnerability in contacts. Impact: Successful exploitation of this vulnerability may affect availability. | May 15, 2026 |
| CVE-2026-41960 | MEDIUM | 5.8 | Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability. | May 15, 2026 |
| CVE-2026-8425 | MEDIUM | 4.3 | The Notify Odoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing … | May 15, 2026 |
| CVE-2026-8398 | CRITICAL | 9.8 | A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distributed from the legitimate website daemon-tools.cc between … | May 15, 2026 |
| CVE-2026-7563 | MEDIUM | 4.3 | The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access in all versions up to, and … | May 15, 2026 |
| CVE-2026-7046 | MEDIUM | 4.9 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'table' parameter in all versions … | May 15, 2026 |
| CVE-2026-6415 | MEDIUM | 6.4 | The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.0.2. This is due … | May 15, 2026 |
| CVE-2026-6403 | HIGH | 7.5 | The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is due to insufficient path validation … | May 15, 2026 |
| CVE-2026-6228 | HIGH | 8.8 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 3.28.36. This is due to insufficient … | May 15, 2026 |
| CVE-2026-5229 | CRITICAL | 9.8 | The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trusting … | May 15, 2026 |