NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2023-42179 Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process. 2026-08-26 N/A None None NVD
CVE-2026-35445 Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler na... 2026-08-26 7.1 NETWORK HIGH NVD
CVE-2026-32258 Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend us... 2026-08-26 8.1 NETWORK HIGH NVD
CVE-2026-32257 Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Bra... 2026-08-26 8.1 NETWORK HIGH NVD
CVE-2020-15878 An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS dat... 2026-08-26 N/A None None NVD
CVE-2020-15876 An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS dat... 2026-08-26 N/A None None NVD
CVE-2020-15874 An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a comman... 2026-08-26 N/A None None NVD
CVE-2026-81036 Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine... 2026-08-26 8.1 NETWORK HIGH NVD
CVE-2026-81035 Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises the caller with the team-access ... 2026-08-26 8.1 NETWORK HIGH NVD
CVE-2026-81034 Netmaker disables certificate verification on the connection to the configured mail server. The sender in pro/email/smtp.go assigns a TLS configuratio... 2026-08-26 6.5 NETWORK MEDIUM NVD
CVE-2026-81033 Automatisch reveals whether an address is registered through the response to its forgot-password request. The controller at packages/backend/src/contr... 2026-08-26 5.3 NETWORK MEDIUM NVD
CVE-2026-81032 NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebSe... 2026-08-26 9.8 NETWORK CRITICAL NVD
CVE-2026-81031 IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the request. The update handler in backend/src... 2026-08-26 7.2 NETWORK HIGH NVD
CVE-2026-81030 Mage AI does not confine the paths accepted by its browser-items API to the project directory. BrowserItemResource in mage_ai/api/resources/BrowserIte... 2026-08-26 6.5 NETWORK MEDIUM NVD
CVE-2026-81029 OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback req... 2026-08-26 8.1 NETWORK HIGH NVD