NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2025-15674 The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-prot... 2026-08-06 2.7 NETWORK LOW NVD
CVE-2025-14561 In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficie... 2026-08-06 9.0 NETWORK CRITICAL NVD
CVE-2025-12317 When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associ... 2026-08-06 5.0 NETWORK MEDIUM NVD
CVE-2024-6541 The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows auth... 2026-08-06 6.8 NETWORK MEDIUM NVD
CVE-2024-39024 In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution. 2026-08-06 8.8 NETWORK HIGH NVD
CVE-2026-68750 Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhau... 2026-08-06 7.5 NETWORK HIGH NVD
CVE-2026-68749 Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to ex... 2026-08-06 7.5 NETWORK HIGH NVD
CVE-2026-68747 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in the CSS scrubber in rrrene html_sa... 2026-08-06 6.1 NETWORK MEDIUM NVD
CVE-2026-66843 Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to lo... 2026-08-06 6.1 NETWORK MEDIUM NVD
CVE-2026-66829 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force v... 2026-08-06 6.1 NETWORK MEDIUM NVD
CVE-2026-66370 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows an unauthenticated remote at... 2026-08-06 6.1 NETWORK MEDIUM NVD
CVE-2026-5423 @neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied, pre-decoded JWT object passed through GraphQL sub... 2026-08-06 8.2 NETWORK HIGH NVD
CVE-2026-53985 Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that... 2026-08-06 7.5 NETWORK HIGH NVD
CVE-2026-53977 OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by sen... 2026-08-06 7.5 NETWORK HIGH NVD
CVE-2026-43622 llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using ma... 2026-08-06 7.8 LOCAL HIGH NVD