Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42239
Total
3441
Critical
12474
High
12431
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-82688 | CRITICAL | 9.1 | A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vol.cgi of the component Virtual … | Aug 31, 2026 |
| CVE-2026-82680 | HIGH | 8.8 | A weakness has been identified in D-Link DSM-G600 1.01. This affects an unknown function of the file /load_file.cgi of the component Multipart Handler. Executing a … | Aug 31, 2026 |
| CVE-2026-82679 | MEDIUM | 6.3 | A security flaw has been discovered in diem-project diem up to 5.1.3. The impacted element is an unknown function of the file dmFrontPlugin/lib/dmWidget/media/dmWidgetContentBaseMediaForm.php of the … | Aug 31, 2026 |
| CVE-2026-82678 | MEDIUM | 4.7 | A vulnerability was identified in diem-project diem up to 5.1.3. The affected element is the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component Administrative … | Aug 31, 2026 |
| CVE-2026-82677 | LOW | 2.4 | A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation … | Aug 31, 2026 |
| CVE-2026-82671 | LOW | 3.4 | A vulnerability has been found in IObit Unlocker 1.3.0.12. This vulnerability affects the function ZwTerminateProcess in the library IObitUnlocker.sys of the component IRP_MJ_DEVICE_CONTROL Handler. The … | Aug 31, 2026 |
| CVE-2026-82670 | MEDIUM | 4.4 | A flaw has been found in IObit Uninstaller 15.5.0.11. This affects the function IRP_MJ_DEVICE_CONTROL in the library IUForceDelete.sys of the component IOCTL Handler. Executing a … | Aug 31, 2026 |
| CVE-2026-82669 | MEDIUM | 5.3 | A vulnerability was detected in klaussilveira GitList 2.0.0. Affected by this issue is the function SimpleXMLElement of the file src/SCM/System/Git/CommandLine.php of the component XML Parsing. … | Aug 31, 2026 |
| CVE-2026-49003 | CRITICAL | 9.6 | Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring module to crash and become paralyzed; simultaneously, they can obtain … | Aug 31, 2026 |
| CVE-2026-19873 | HIGH | 7.5 | HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. When a Repeatable element … | Aug 31, 2026 |
| CVE-2026-82875 | MEDIUM | 5.5 | ToolJet before v3.16.208 contains an authorization bypass vulnerability in TooljetDB controller endpoints that accept organizationId from URL path without verifying it matches the authenticated user's … | Aug 31, 2026 |
| CVE-2026-82874 | CRITICAL | 9.9 | ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder … | Aug 31, 2026 |
| CVE-2026-82873 | MEDIUM | 5.0 | ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/resources/export endpoint that allow authenticated users to disclose TooljetDB table schemas across workspace boundaries and … | Aug 31, 2026 |
| CVE-2026-82872 | CRITICAL | 9.1 | ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can … | Aug 31, 2026 |
| CVE-2026-82871 | HIGH | 7.7 | ToolJet before v3.16.208 fails to validate organization membership in database read routes, allowing any authenticated user to access other organizations' table schemas and row data. … | Aug 31, 2026 |
| CVE-2026-82870 | CRITICAL | 9.6 | ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in … | Aug 31, 2026 |
| CVE-2026-82869 | HIGH | 7.7 | ToolJet Database versions before v3.16.44 contain a privilege escalation vulnerability in the join_tables endpoint that grants JOIN_TABLES ability to all authenticated users without role or … | Aug 31, 2026 |
| CVE-2026-82868 | MEDIUM | 6.1 | @pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the SVG schema plugin that renders user-supplied SVG content directly to innerHTML without sanitization. Attackers can … | Aug 31, 2026 |
| CVE-2026-82867 | MEDIUM | 6.1 | @pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerability in the Select schema plugin that fails to sanitize option values before interpolating them into HTML via … | Aug 31, 2026 |
| CVE-2026-82866 | MEDIUM | 6.8 | @pdfme/common before 5.5.10 contains a server-side request forgery vulnerability in the getB64BasePdf function that fetches arbitrary URLs without validation when basePdf is attacker-controlled. Attackers who … | Aug 31, 2026 |
| CVE-2026-82865 | MEDIUM | 4.4 | pdfme schemas before 5.5.10 contains a cross-site scripting vulnerability in the multiVariableText property panel that assigns unsanitized i18n label values to innerHTML. Attackers who control … | Aug 31, 2026 |
| CVE-2026-82864 | MEDIUM | 6.5 | pdfme pdf-lib versions before 5.5.10 contain an unbounded buffer growth vulnerability in the DecodeStream.ensureBuffer() method that allows attackers to cause denial of service by supplying … | Aug 31, 2026 |
| CVE-2026-82863 | LOW | 3.3 | @hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without … | Aug 31, 2026 |
| CVE-2026-82862 | HIGH | 8.4 | Hulumi versions before v1.3.2 resolve the threat-model helper script from an unsafe root, allowing workspace files to shadow the intended helper script. Attackers can place … | Aug 31, 2026 |
| CVE-2026-82861 | HIGH | 7.5 | @hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attackers to submit spoofed SecureBucket parent evidence during policy evaluation. Attackers can bypass … | Aug 31, 2026 |