Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
27697
Total
2080
Critical
8292
High
8500
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-41663 | LOW | 3.5 | Admidio is an open-source user management solution. Prior to version 5.0.9, several administrative operations in Admidio's preferences module (database backup, test email, htaccess generation) fire … | May 07, 2026 |
| CVE-2026-41662 | MEDIUM | 5.2 | Admidio is an open-source user management solution. Prior to version 5.0.9, Role::stopMembership() does not verify whether removing a user from the administrator role leaves zero … | May 07, 2026 |
| CVE-2026-41661 | MEDIUM | 6.1 | Admidio is an open-source user management solution. Prior to version 5.0.9, an unauthenticated attacker can execute arbitrary JavaScript in any Admidio user's browser through a … | May 07, 2026 |
| CVE-2026-41660 | HIGH | 7.1 | Admidio is an open-source user management solution. Prior to version 5.0.9, a logic error in Admidio's two-factor authentication reset inverts the authorization check. Non-admin users … | May 07, 2026 |
| CVE-2026-41659 | LOW | 2.7 | Admidio is an open-source user management solution. Prior to version 5.0.9, the member assignment DataTables endpoint (members_assignment_data.php) includes hidden profile fields (BIRTHDAY, STREET, CITY, POSTCODE, … | May 07, 2026 |
| CVE-2026-41658 | MEDIUM | 6.5 | Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio inventory module enforces authorization for destructive operations (delete, retire, reinstate) only in … | May 07, 2026 |
| CVE-2026-41657 | MEDIUM | 4.9 | Admidio is an open-source user management solution. Prior to version 5.0.9, the contacts_data.php endpoint uses a weaker permission check (isAdministratorUsers(), requiring only rol_edit_user=true) than the … | May 07, 2026 |
| CVE-2026-41656 | MEDIUM | 4.5 | Admidio is an open-source user management solution. Prior to version 5.0.9, the add mode in modules/documents-files.php accepts a name parameter validated only as 'string' type … | May 07, 2026 |
| CVE-2026-41655 | MEDIUM | 6.5 | Admidio is an open-source user management solution. Prior to version 5.0.9, the ecard_preview.php endpoint does not validate that the ecard_template POST parameter is a safe … | May 07, 2026 |
| CVE-2026-41640 | HIGH | 7.5 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the queryParentSQL() function in the core database package … | May 07, 2026 |
| CVE-2026-41587 | UNKNOWN | — | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From version 0.26.0.0 to before version … | May 07, 2026 |
| CVE-2026-41203 | UNKNOWN | — | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.5.0, ci4ms Theme::upload … | May 07, 2026 |
| CVE-2026-41202 | UNKNOWN | — | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.5.0, ci4ms Backup::restore … | May 07, 2026 |
| CVE-2026-41201 | CRITICAL | 9.1 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. In version 0.31.4.0, an attacker can … | May 07, 2026 |
| CVE-2026-41142 | HIGH | 8.8 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to … | May 07, 2026 |
| CVE-2026-41004 | MEDIUM | 4.4 | When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from … | May 07, 2026 |
| CVE-2026-41002 | HIGH | 7.2 | The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config … | May 07, 2026 |
| CVE-2026-40982 | CRITICAL | 9.1 | Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request … | May 07, 2026 |
| CVE-2026-40981 | HIGH | 7.5 | When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially … | May 07, 2026 |
| CVE-2026-40004 | MEDIUM | 5.5 | There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges. | May 07, 2026 |
| CVE-2026-4807 | MEDIUM | 6.5 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.6.10.6. This is due to a flawed … | May 07, 2026 |
| CVE-2026-44600 | LOW | 3.7 | Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-2026-010. | May 07, 2026 |
| CVE-2026-44599 | LOW | 3.7 | Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008. | May 07, 2026 |
| CVE-2026-6222 | MEDIUM | 5.3 | The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1. This is due to the `processRequest()` method … | May 07, 2026 |
| CVE-2026-40003 | MEDIUM | 5.1 | ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the lack of target address validation in the USB … | May 07, 2026 |