NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-34191 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_orac... 2026-08-06 9.1 NETWORK CRITICAL NVD
CVE-2026-32327 A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and... 2026-08-06 9.1 NETWORK CRITICAL NVD
CVE-2026-15246 The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, nor check a nonce or the user's ... 2026-08-06 4.3 NETWORK MEDIUM NVD
CVE-2025-49506 APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentia... 2026-08-06 7.5 NETWORK HIGH NVD
CVE-2026-64993 Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker co... 2026-08-06 6.8 NETWORK MEDIUM NVD
CVE-2026-5134 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CM... 2026-08-06 9.8 NETWORK CRITICAL NVD
CVE-2026-16731 OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may a... 2026-08-06 8.3 NETWORK HIGH NVD
CVE-2026-16316 OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame processing. A specially craft... 2026-08-06 4.3 ADJACENT_NETWORK MEDIUM NVD
CVE-2026-16315 OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may a... 2026-08-06 8.7 NETWORK HIGH NVD
CVE-2026-12605 In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled h... 2026-08-06 9.6 NETWORK CRITICAL NVD
CVE-2026-70556 Hubzilla versions prior to 11.4 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint handled by Zotlabs\Module\Autho... 2026-08-06 4.3 NETWORK MEDIUM NVD
CVE-2026-66733 Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enqueuePacket() that allows unauthe... 2026-08-06 7.5 NETWORK HIGH NVD
CVE-2026-66732 Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager where established connections are... 2026-08-06 5.9 NETWORK MEDIUM NVD
CVE-2026-15599 Unverified ownership vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-domain-joiner allows Privilege Abuse. This issue... 2026-08-06 3.3 LOCAL LOW NVD
CVE-2026-8166 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Industry and Trade Inc. E-Logo Pur... 2026-08-06 5.4 NETWORK MEDIUM NVD