NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-3430 The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauth... 2026-08-06 8.6 NETWORK HIGH NVD
CVE-2026-18427 @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent direc... 2026-08-06 7.5 NETWORK HIGH NVD
CVE-2026-18359 Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to mak... 2026-08-06 8.5 NETWORK HIGH NVD
CVE-2026-18277 Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant... 2026-08-06 7.1 NETWORK HIGH NVD
CVE-2026-18276 Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any documen... 2026-08-06 4.3 NETWORK MEDIUM NVD
CVE-2026-18275 Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to ... 2026-08-06 6.5 NETWORK MEDIUM NVD
CVE-2026-18258 Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a... 2026-08-06 8.8 NETWORK HIGH NVD
CVE-2026-70646 aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request... 2026-08-06 7.5 NETWORK HIGH NVD
CVE-2026-70637 LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause undefined behavior by issuing LI... 2026-08-06 5.9 NETWORK MEDIUM NVD
CVE-2026-67261 Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI c... 2026-08-06 9.8 NETWORK CRITICAL NVD
CVE-2026-54489 Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. A... 2026-08-06 9.1 NETWORK CRITICAL NVD
CVE-2026-53976 OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unaut... 2026-08-06 9.1 NETWORK CRITICAL NVD
CVE-2026-53975 OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by... 2026-08-06 9.8 NETWORK CRITICAL NVD
CVE-2026-34502 Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from... 2026-08-06 7.5 NETWORK HIGH NVD
CVE-2026-34501 Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.... 2026-08-06 7.5 NETWORK HIGH NVD