Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

27385
Total
2080
Critical
8289
High
8496
Medium
CVE ID Severity Score Description Published
CVE-2025-71302 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: drm/panthor: fix for dma-fence safe access rules Commit 506aa8b02a8d6 ("dma-fence: Add safe access helpers and … May 08, 2026
CVE-2025-71301 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around vmap/vunmap Acquire and release the GEM object's reservation lock … May 08, 2026
CVE-2025-71300 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: Revert "arm64: zynqmp: Add an OP-TEE node to the device tree" This reverts commit 06d22ed6b6635b17551f386b50bb5aaff9b75fbe. … May 08, 2026
CVE-2025-71299 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing The recent … May 08, 2026
CVE-2025-71298 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around madvise Acquire and release the GEM object's reservation lock … May 08, 2026
CVE-2025-71297 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: 8822b: Avoid WARNING in rtw8822b_config_trx_mode() rtw8822b_set_antenna() can be called from userspace when the … May 08, 2026
CVE-2025-71296 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: drm/tests: shmem: Hold reservation lock around purge Acquire and release the GEM object's reservation lock … May 08, 2026
CVE-2026-8077 UNKNOWN Lack of proper authorization implementation in the CashDro 3 web administration panel, version 24.01.00.26. The backend lacks authorization controls, leaving security entirely to the frontend. … May 08, 2026
CVE-2026-25199 UNKNOWN Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.0.0. The … May 08, 2026
CVE-2026-25077 UNKNOWN Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hypervisor. Due … May 08, 2026
CVE-2025-69233 MEDIUM 6.5 Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of the platform are … May 08, 2026
CVE-2025-66467 HIGH 8.0 Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user creates … May 08, 2026
CVE-2025-66172 UNKNOWN The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this … May 08, 2026
CVE-2025-66171 UNKNOWN The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this … May 08, 2026
CVE-2025-66170 UNKNOWN The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0. Anyone with authenticated user-account access in CloudStack 4.21.0.0+ environments, where this … May 08, 2026
CVE-2022-50994 HIGH 8.1 DrayTek Vigor 2960 firmware versions prior to 1.5.1.4 contain an OS command injection vulnerability in the CGI login handler that allows unauthenticated remote attackers to … May 08, 2026
CVE-2026-8153 CRITICAL 9.8 OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.21.1 allows unauthenticated attacker to craft commands that will execute code … May 08, 2026
CVE-2026-8076 UNKNOWN Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of numeric PINs for user authentication. The system … May 08, 2026
CVE-2026-3318 UNKNOWN Open redirection vulnerability in the latest demo version of the Cradle eCommerce platform. The vulnerability occurs in the login form endpoint, where the ‘returnUrl’ parameter … May 08, 2026
CVE-2026-7650 MEDIUM 6.4 The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the `e2pdf-download` shortcode … May 08, 2026
CVE-2026-7475 MEDIUM 6.4 The Sky Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sky-custom-scripts` custom post type in all versions up to, and including, … May 08, 2026
CVE-2026-6213 UNKNOWN A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root … May 08, 2026
CVE-2026-5341 MEDIUM 6.4 The NMR Strava activities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `strava_nmr_connect` shortcode in all versions up to, and including, … May 08, 2026
CVE-2026-7330 HIGH 7.2 The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.8.8 This is due to insufficient … May 08, 2026
CVE-2026-5127 HIGH 8.8 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in … May 08, 2026