Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51620
Total
4095
Critical
15305
High
14964
Medium
CVE ID Severity Score Description Published
CVE-2026-66035 HIGH 7.5 libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in … Jul 24, 2026
CVE-2026-66034 HIGH 7.5 libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds … Jul 24, 2026
CVE-2026-66033 HIGH 7.5 libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server … Jul 24, 2026
CVE-2026-66032 HIGH 8.8 libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt … Jul 24, 2026
CVE-2026-65711 HIGH 7.2 sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands as the web server process user by … Jul 24, 2026
CVE-2026-65710 HIGH 7.1 sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag to trigger unauthorized decryption and persistent storage … Jul 24, 2026
CVE-2026-65709 HIGH 8.3 sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, … Jul 24, 2026
CVE-2026-65708 HIGH 8.1 sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they … Jul 24, 2026
CVE-2026-65707 MEDIUM 6.5 Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract arbitrary database contents by submitting unsanitized POST parameters to the … Jul 24, 2026
CVE-2026-65623 UNKNOWN — Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via CPU exhaustion during WebSocket fragment reassembly. The size guard 'Elixir.Bandit.WebSocket.Connection':oversize_message?/2 called … Jul 24, 2026
CVE-2026-66027 HIGH 8.3 Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging … Jul 24, 2026
CVE-2026-65693 HIGH 7.2 Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into … Jul 24, 2026
CVE-2026-64255 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers Three BA session handlers … Jul 24, 2026
CVE-2026-64254 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR When BAR_PEER_SPAD and … Jul 24, 2026
CVE-2026-64253 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: kernel/fork: clear PF_BLOCK_TS in copy_process() PF_BLOCK_TS is only set in blk_time_get_ns() when current->plug is non-NULL, … Jul 24, 2026
CVE-2026-64252 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: MIPS: DEC: Prevent initial console buffer from landing in XKPHYS In 64-bit configurations calling the … Jul 24, 2026
CVE-2026-64251 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next() pwrseq_debugfs_seq_next() declares 'next' with __free(put_device), which causes put_device() to … Jul 24, 2026
CVE-2026-64250 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: LoongArch: Report dying CPU to RCU in stop_this_cpu() This is a port of MIPS commit … Jul 24, 2026
CVE-2026-64249 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: fpga: region: fix use-after-free in child_regions_with_firmware() Move of_node_put(child_region) after the error print to avoid accessing … Jul 24, 2026
CVE-2026-64248 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: MIPS: smp: report dying CPU to RCU in stop_this_cpu() smp_send_stop() parks all secondary CPUs in … Jul 24, 2026
CVE-2026-64247 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: KVM: x86: hyper-v: Bound the bank index when querying sparse banks When checking if a … Jul 24, 2026
CVE-2026-64246 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() Move of_node_put(dn) after the of_match_node() call, which … Jul 24, 2026
CVE-2026-64245 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: fbdev: modedb: fix a possible UAF in fb_find_mode() If mode_option is NULL, it is assigned … Jul 24, 2026
CVE-2026-64244 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: drivers/base/memory: set mem->altmap after successful device registration If __add_memory_block() fails at xa_store() (under memory pressure … Jul 24, 2026
CVE-2026-64243 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: simple-mux: Fix enum control bounds check simple_mux_control_put() rejects values greater than e->items, but … Jul 24, 2026