Ad

CVE Vulnerability Database

Complete database of CVE vulnerabilities. Track critical security threats, exploits and patches. Updated daily from NVD NIST.

CVE-2026-21667

8.8

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

Veeam
Details

CVE-2026-21666

8.8

A vulnerability allowing an authenticated domain user to perform remote code execution (RCE) on the Backup Server.

Veeam
Details

CVE-2026-3099

7.3

A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued nonces or enforce the required incrementing nonce-count (nc) attribute. This …

Gnome
Details

CVE-2026-2987

6.1

The Simple Ajax Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'c' parameter in versions up to, and including, 20260217 due to insufficient input sanitization and …

WordPress
Details

CVE-2026-2514

8.6

In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed …

In Progress
Details

CVE-2026-2513

8.6

A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions …

Progress
Details

CVE-2026-0809

6.3

Use of a custom token encoding algorithm in Streamsoft Prestiż software allows the value of the KSeF (Krajowy System e-Faktur) token to be guessed after analyzing how tokens with know …

Details

CVE-2026-4040

4.8

A vulnerability was identified in OpenClaw up to 2026.2.17. This issue affects the function tools.exec.safeBins of the component File Existence Handler. The manipulation leads to information exposure through discrepancy. The …

Openclaw
Details

CVE-2026-4039

5.3

A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverrides of the component Skill Env Handler. Executing a manipulation can lead to code injection. It is possible …

Openclaw
Details

CVE-2026-3989

7.8

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code …

SGLangs
Details
684/3864