Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51667
Total
4097
Critical
15338
High
14987
Medium
CVE ID Severity Score Description Published
CVE-2026-13061 MEDIUM 4.3 An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is … Jul 22, 2026
CVE-2026-13060 MEDIUM 6.5 An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency … Jul 22, 2026
CVE-2026-13059 HIGH 8.1 An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to … Jul 22, 2026
CVE-2026-13058 UNKNOWN — An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with an incomplete set … Jul 22, 2026
CVE-2026-13057 MEDIUM 5.3 An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In sharded topologies, the $search and $searchMeta aggregation … Jul 22, 2026
CVE-2026-13056 MEDIUM 6.5 Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to … Jul 22, 2026
CVE-2026-13055 MEDIUM 6.5 The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to handle compound wildcard index … Jul 22, 2026
CVE-2026-3482 MEDIUM 5.3 IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 could allow an unauthenticated user to … Jul 22, 2026
CVE-2026-22049 UNKNOWN — ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully … Jul 22, 2026
CVE-2026-16624 UNKNOWN — Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then … Jul 22, 2026
CVE-2026-65650 MEDIUM 4.3 Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload. Jul 22, 2026
CVE-2026-64835 HIGH 8.8 FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds … Jul 22, 2026
CVE-2026-64834 HIGH 7.5 FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service … Jul 22, 2026
CVE-2026-64833 HIGH 7.1 FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying … Jul 22, 2026
CVE-2026-64832 HIGH 8.8 FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by … Jul 22, 2026
CVE-2026-16157 UNKNOWN — Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Installing the software outside of the Program Files directory, or on … Jul 22, 2026
CVE-2026-7328 UNKNOWN — Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode allows a privileged local attacker to cause a denial of service … Jul 22, 2026
CVE-2026-65013 HIGH 8.8 Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources … Jul 22, 2026
CVE-2026-65012 MEDIUM 5.3 InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_folder endpoint that accepts attacker-controlled scan_path parameters. Unauthenticated attackers can recursively enumerate arbitrary … Jul 22, 2026
CVE-2026-65011 MEDIUM 4.3 Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint that allows authenticated users to clone any event definition. … Jul 22, 2026
CVE-2026-64831 HIGH 8.8 FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses … Jul 22, 2026
CVE-2026-64830 HIGH 8.8 FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by … Jul 22, 2026
CVE-2026-16615 MEDIUM 6.8 A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number … Jul 22, 2026
CVE-2026-64828 MEDIUM 6.1 Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary HTML and JavaScript through the order notes field … Jul 22, 2026
CVE-2026-49499 HIGH 8.8 Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote … Jul 22, 2026