Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51605
Total
4093
Critical
15302
High
14954
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-57530 | MEDIUM | 5.4 | Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary … | Jul 24, 2026 |
| CVE-2026-54342 | HIGH | 8.1 | In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a … | Jul 24, 2026 |
| CVE-2026-48037 | UNKNOWN | — | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, AccountFoundation reuse paths silently downgrade GuardDuty … | Jul 24, 2026 |
| CVE-2026-48036 | UNKNOWN | — | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI … | Jul 24, 2026 |
| CVE-2026-48035 | UNKNOWN | — | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers using AccountFoundation could ship an … | Jul 24, 2026 |
| CVE-2026-48034 | UNKNOWN | — | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, there is a bypass via decoy … | Jul 24, 2026 |
| CVE-2026-48033 | UNKNOWN | — | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, policy packs can be bypassed by … | Jul 24, 2026 |
| CVE-2026-48032 | UNKNOWN | — | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, IAM-role policy checks can be bypassed … | Jul 24, 2026 |
| CVE-2026-48021 | CRITICAL | 9.1 | In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake … | Jul 24, 2026 |
| CVE-2026-17107 | HIGH | 8.5 | A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends … | Jul 24, 2026 |
| CVE-2026-66035 | HIGH | 7.5 | libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in … | Jul 24, 2026 |
| CVE-2026-66034 | HIGH | 7.5 | libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds … | Jul 24, 2026 |
| CVE-2026-66033 | HIGH | 7.5 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server … | Jul 24, 2026 |
| CVE-2026-66032 | HIGH | 8.8 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt … | Jul 24, 2026 |
| CVE-2026-65711 | HIGH | 7.2 | sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands as the web server process user by … | Jul 24, 2026 |
| CVE-2026-65710 | HIGH | 7.1 | sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag to trigger unauthorized decryption and persistent storage … | Jul 24, 2026 |
| CVE-2026-65709 | HIGH | 8.3 | sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, … | Jul 24, 2026 |
| CVE-2026-65708 | HIGH | 8.1 | sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they … | Jul 24, 2026 |
| CVE-2026-65707 | MEDIUM | 6.5 | Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract arbitrary database contents by submitting unsanitized POST parameters to the … | Jul 24, 2026 |
| CVE-2026-65623 | UNKNOWN | — | Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via CPU exhaustion during WebSocket fragment reassembly. The size guard 'Elixir.Bandit.WebSocket.Connection':oversize_message?/2 called … | Jul 24, 2026 |
| CVE-2026-66027 | HIGH | 8.3 | Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging … | Jul 24, 2026 |
| CVE-2026-65693 | HIGH | 7.2 | Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into … | Jul 24, 2026 |
| CVE-2026-64255 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers Three BA session handlers … | Jul 24, 2026 |
| CVE-2026-64254 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR When BAR_PEER_SPAD and … | Jul 24, 2026 |
| CVE-2026-64253 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: kernel/fork: clear PF_BLOCK_TS in copy_process() PF_BLOCK_TS is only set in blk_time_get_ns() when current->plug is non-NULL, … | Jul 24, 2026 |