Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

27385
Total
2080
Critical
8289
High
8496
Medium
CVE ID Severity Score Description Published
CVE-2024-27686 HIGH 7.5 Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data … May 08, 2026
CVE-2023-47268 UNKNOWN In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrary code on a host where the project is sliced and … May 08, 2026
CVE-2026-8148 UNKNOWN NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks. May 08, 2026
CVE-2026-8138 HIGH 8.8 A vulnerability was found in Tenda CX12L 16.03.53.12. This issue affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg”. The manipulation results in stack-based buffer overflow. … May 08, 2026
CVE-2026-8137 HIGH 8.8 A vulnerability has been found in Totolink X5000R 9.1.0u.6369_B20230113. This vulnerability affects the function sub_458E40 of the file /boafrm/formDdns. The manipulation of the argument submit-url … May 08, 2026
CVE-2026-42279 MEDIUM 5.8 solidtime is an open-source time-tracking app. In version 0.12.0, the PUT /api/v1/organizations/{organization}/time-entries/{timeEntry} API accepts a route-bound timeEntry from another organization when the caller has time-entries:update:all … May 08, 2026
CVE-2026-42278 UNKNOWN UltraDAG is a minimal DAG-BFT blockchain in Rust. Prior to commit fb6ef59, the UltraDAG StateEngine implementation of SmartTransferTx contains a critical logic flaw in its … May 08, 2026
CVE-2026-42277 MEDIUM 6.5 Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the GET /chat/file/{file_id} endpoint allows any authenticated user to download any other … May 08, 2026
CVE-2026-42276 MEDIUM 4.3 Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the POST /chat/stop-chat-session/{chat_session_id} endpoint lets any authenticated user stop any other user's … May 08, 2026
CVE-2023-42346 UNKNOWN Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host. May 08, 2026
CVE-2023-42345 MEDIUM 6.1 A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp. May 08, 2026
CVE-2023-42344 HIGH 7.3 Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet. May 08, 2026
CVE-2023-42343 MEDIUM 6.1 A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type. May 08, 2026
CVE-2022-45899 MEDIUM 6.5 Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacters in the Log … May 08, 2026
CVE-2022-26523 MEDIUM 5.3 The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in … May 08, 2026
CVE-2022-26522 HIGH 7.8 The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in … May 08, 2026
CVE-2022-23961 MEDIUM 6.1 In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability can be exploited by unauthenticated remote … May 08, 2026
CVE-2026-8136 LOW 2.4 A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /index.php?page=users. Executing a manipulation … May 08, 2026
CVE-2026-8133 HIGH 7.3 A security vulnerability has been detected in zyx0814 FilePress up to 2.2.0. Affected by this vulnerability is an unknown functionality of the file dzz/shares/admin.php of … May 08, 2026
CVE-2026-8132 HIGH 7.3 A weakness has been identified in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /login.php. This manipulation of the argument … May 08, 2026
CVE-2026-8131 HIGH 7.3 A security flaw has been discovered in SourceCodester SUP Online Shopping 1.0. This impacts an unknown function of the file /admin/replymsg.php. The manipulation of the … May 08, 2026
CVE-2026-8130 HIGH 7.3 A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. This affects an unknown function of the file /admin/message.php. The manipulation of the argument seenid … May 08, 2026
CVE-2026-8129 HIGH 7.3 A vulnerability was determined in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file wishlist.php. Executing a manipulation of … May 08, 2026
CVE-2026-44298 MEDIUM 4.1 Kimai is an open-source time tracking application. From version 2.32.0 to before version 2.56.0, users with the role System-Admin (ROLE_SYSTE_ADMIN) and the permission upload_invoice_template can … May 08, 2026
CVE-2026-43944 UNKNOWN electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerable to arbitrary local code execution via deep links, CLI --opts, … May 08, 2026