Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

27385
Total
2080
Critical
8289
High
8496
Medium
CVE ID Severity Score Description Published
CVE-2026-44928 LOW 2.9 In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal. May 08, 2026
CVE-2026-44927 LOW 2.9 In uriparser before 1.0.2, there is pointer difference truncation to int in various places. May 08, 2026
CVE-2026-43284 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a … May 08, 2026
CVE-2013-10075 UNKNOWN Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create a session that does not exist. This can … May 08, 2026
CVE-2026-8149 UNKNOWN A vulnerability in Legion of the Bouncy Castle Inc. BC-FJA BC-FIPS on Linux, X86_64, AVX, AVX-512f. This vulnerability is associated with program files gcm128w, gcm512w. … May 08, 2026
CVE-2026-8069 UNKNOWN PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal … May 08, 2026
CVE-2026-4935 HIGH 8.6 The OttoKit: All-in-One Automation Platform WordPress plugin before 1.1.23 does not properly sanitize user input before using it in a SQL statement, which could allow … May 08, 2026
CVE-2026-44916 LOW 3.0 In OpenStack Ironic through 35.x, instance_info['ks_template'] is rendered without sandboxing. May 08, 2026
CVE-2025-69691 UNKNOWN Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available … May 08, 2026
CVE-2025-69690 UNKNOWN Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. … May 08, 2026
CVE-2025-69599 UNKNOWN RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH environment variable. NOTE: this is … May 08, 2026
CVE-2025-67888 HIGH 7.3 An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /admin/index.php (when the "api" parameter … May 08, 2026
CVE-2025-67887 UNKNOWN 1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a … May 08, 2026
CVE-2025-67886 UNKNOWN Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a … May 08, 2026
CVE-2025-55449 UNKNOWN AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT. May 08, 2026
CVE-2023-46453 UNKNOWN Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both a valid SQL … May 08, 2026
CVE-2024-53326 UNKNOWN LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(), leading to code execution. May 08, 2026
CVE-2024-51092 CRITICAL 9.1 LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), SettingsController.php's update(), and PollDevice.php's initRrdDirectory(). May 08, 2026
CVE-2024-46508 UNKNOWN yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than … May 08, 2026
CVE-2024-46507 UNKNOWN A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the … May 08, 2026
CVE-2024-45257 UNKNOWN A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server … May 08, 2026
CVE-2024-33724 UNKNOWN SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php. May 08, 2026
CVE-2024-33722 UNKNOWN SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[]. May 08, 2026
CVE-2024-33288 UNKNOWN Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the Admin login page. May 08, 2026
CVE-2024-30167 MEDIUM 6.3 /cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary commands as root via a POST request that carries a serverName … May 08, 2026