Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26897
Total
1982
Critical
8080
High
8318
Medium
CVE ID Severity Score Description Published
CVE-2026-44423 MEDIUM 6.5 ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/sessions/:uid returns the full session object for any authenticated caller, without scoping by the caller's … May 13, 2026
CVE-2026-44369 UNKNOWN CVAT is an open source interactive video and image annotation tool for computer vision. From 2.5.0 to 2.63.0, an attacker who is able to create … May 13, 2026
CVE-2026-44195 MEDIUM 5.3 OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler allows an unauthenticated attacker to continuously … May 13, 2026
CVE-2026-44194 CRITICAL 9.1 OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a … May 13, 2026
CVE-2026-44193 CRITICAL 9.1 OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading to Remote … May 13, 2026
CVE-2026-42463 UNKNOWN SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cross-Workspace IDOR (Insecure Direct Object Reference) … May 13, 2026
CVE-2026-40328 UNKNOWN Rejected reason: This CVE is a duplicate of another CVE. May 13, 2026
CVE-2026-40327 UNKNOWN Rejected reason: This CVE is a duplicate of another CVE. May 13, 2026
CVE-2026-32993 HIGH 8.3 Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response. May 13, 2026
CVE-2026-32992 HIGH 8.2 SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials. May 13, 2026
CVE-2026-29205 HIGH 8.6 Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints. May 13, 2026
CVE-2026-8328 UNKNOWN The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual … May 13, 2026
CVE-2026-45714 CRITICAL 9.1 CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates, … May 13, 2026
CVE-2026-45708 HIGH 7.2 CubeCart is an ecommerce software solution. Prior to 6.7.3, an admin with documents edit permission can save raw <?php … ?> into the Invoice Editor. … May 13, 2026
CVE-2026-45229 HIGH 8.8 Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated attackers to overwrite administrator credentials by posting an … May 13, 2026
CVE-2026-45228 MEDIUM 5.4 Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the template renders push_config key names using Vue.js's v-html … May 13, 2026
CVE-2026-45055 HIGH 8.1 CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the Host request header at bootstrap, with no … May 13, 2026
CVE-2026-45054 MEDIUM 4.9 CubeCart is an ecommerce software solution. Prior to 6.7.0, the admin orders-transactions listing page (admin.php?_g=orders&node=transactions) builds a raw ORDER BY SQL fragment from the attacker-controlled … May 13, 2026
CVE-2026-45053 CRITICAL 9.1 CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists in the REST API File Manager endpoint (POST /api/v1/files) … May 13, 2026
CVE-2026-44418 UNKNOWN EcclesiaCRM is CRM Software for church management. In 8.0.0 and earlier, the ValidateInput() function's default case in EcclesiaCRM's query view passes user-supplied POST parameters directly … May 13, 2026
CVE-2026-44381 UNKNOWN MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-controlled ordering parameters … May 13, 2026
CVE-2026-44380 UNKNOWN MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerability in the authentication key reset functionality allowed … May 13, 2026
CVE-2026-44379 UNKNOWN MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4122 UUID validation on the uuid … May 13, 2026
CVE-2026-44377 CRITICAL 9.1 CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates … May 13, 2026
CVE-2026-44376 MEDIUM 6.1 CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the CubeCart v6.x search feature. Due to a logic … May 13, 2026