Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51620
Total
4095
Critical
15305
High
14964
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-55729 | UNKNOWN | — | Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to leak stored … | Jul 24, 2026 |
| CVE-2026-55728 | UNKNOWN | — | Stack-based Buffer Overflow (CWE-121) in `/usr/bin/ltsudo` `cmd_ipaddr_conflict` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group … | Jul 24, 2026 |
| CVE-2026-49326 | MEDIUM | 6.5 | Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest service has 3 steps, open, fetch(possible multiple times), close. … | Jul 24, 2026 |
| CVE-2026-17059 | MEDIUM | 6.5 | A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. … | Jul 24, 2026 |
| CVE-2026-16802 | MEDIUM | 6.5 | Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to … | Jul 24, 2026 |
| CVE-2026-16801 | HIGH | 8.8 | Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable … | Jul 24, 2026 |
| CVE-2026-16800 | HIGH | 8.8 | Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule … | Jul 24, 2026 |
| CVE-2026-16799 | MEDIUM | 5.0 | Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader … | Jul 24, 2026 |
| CVE-2026-16798 | MEDIUM | 6.5 | Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped … | Jul 24, 2026 |
| CVE-2026-12504 | UNKNOWN | — | Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local … | Jul 24, 2026 |
| CVE-2026-12503 | UNKNOWN | — | Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker … | Jul 24, 2026 |
| CVE-2026-12502 | UNKNOWN | — | Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker … | Jul 24, 2026 |
| CVE-2026-12496 | UNKNOWN | — | Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 … | Jul 24, 2026 |
| CVE-2026-17048 | MEDIUM | 5.5 | A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system … | Jul 24, 2026 |
| CVE-2026-9765 | HIGH | 7.1 | Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are “Broken” when a user can … | Jul 24, 2026 |
| CVE-2026-7484 | MEDIUM | 5.3 | External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects AVESİS: … | Jul 24, 2026 |
| CVE-2026-66144 | HIGH | 7.5 | Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the API it can cause a denial of service … | Jul 24, 2026 |
| CVE-2026-66143 | HIGH | 7.5 | It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies, which may … | Jul 24, 2026 |
| CVE-2026-66142 | HIGH | 7.5 | Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested structures, which may lead to a denial … | Jul 24, 2026 |
| CVE-2026-66010 | MEDIUM | 6.1 | DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive … | Jul 24, 2026 |
| CVE-2026-66009 | UNKNOWN | — | Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages that name required custom input fields even when … | Jul 24, 2026 |
| CVE-2026-66008 | UNKNOWN | — | Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target class names through GraphQL validation and input-coercion error … | Jul 24, 2026 |
| CVE-2026-46452 | MEDIUM | 5.3 | Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken data toward application resulting in memory pressure and … | Jul 24, 2026 |
| CVE-2026-45816 | HIGH | 7.5 | NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would trigger before NULL dereference) … | Jul 24, 2026 |
| CVE-2026-45815 | HIGH | 7.5 | Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser. Severity is medium as … | Jul 24, 2026 |