NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-16269 The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the AP... 2026-08-08 4.8 NETWORK MEDIUM NVD
CVE-2026-16267 The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, all... 2026-08-08 8.1 NETWORK HIGH NVD
CVE-2026-13505 In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), sensitive key material h... 2026-08-08 8.7 NETWORK HIGH NVD
CVE-2026-8798 In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried the CPU entropy instructions w... 2026-08-08 8.7 NETWORK HIGH NVD
CVE-2026-52880 Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable den... 2026-08-07 7.5 NETWORK HIGH NVD
CVE-2026-52879 Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a n... 2026-08-07 7.5 NETWORK HIGH NVD
CVE-2026-52878 Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered b... 2026-08-07 7.5 NETWORK HIGH NVD
CVE-2026-49343 Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie syncers are vulnerable to a r... 2026-08-07 5.9 NETWORK MEDIUM NVD
CVE-2026-48122 Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP VS Code extension prior to ve... 2026-08-07 5.4 LOCAL MEDIUM NVD
CVE-2026-48120 Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup ... 2026-08-07 8.6 LOCAL HIGH NVD
CVE-2026-48047 XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to versions 16.10.17, 17.4.9, and... 2026-08-07 5.9 NETWORK MEDIUM NVD
CVE-2026-48026 lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84... 2026-08-07 8.7 NETWORK HIGH NVD
CVE-2026-47249 Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-a... 2026-08-07 7.5 NETWORK HIGH NVD
CVE-2026-47127 Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-URL handler at `GET /api/v1/subs... 2026-08-07 6.5 NETWORK MEDIUM NVD
CVE-2026-46409 OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desk... 2026-08-07 9.6 NETWORK CRITICAL NVD