Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51667
Total
4097
Critical
15338
High
14987
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-13061 | MEDIUM | 4.3 | An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is … | Jul 22, 2026 |
| CVE-2026-13060 | MEDIUM | 6.5 | An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency … | Jul 22, 2026 |
| CVE-2026-13059 | HIGH | 8.1 | An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to … | Jul 22, 2026 |
| CVE-2026-13058 | UNKNOWN | — | An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with an incomplete set … | Jul 22, 2026 |
| CVE-2026-13057 | MEDIUM | 5.3 | An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In sharded topologies, the $search and $searchMeta aggregation … | Jul 22, 2026 |
| CVE-2026-13056 | MEDIUM | 6.5 | Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to … | Jul 22, 2026 |
| CVE-2026-13055 | MEDIUM | 6.5 | The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to handle compound wildcard index … | Jul 22, 2026 |
| CVE-2026-3482 | MEDIUM | 5.3 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 could allow an unauthenticated user to … | Jul 22, 2026 |
| CVE-2026-22049 | UNKNOWN | — | ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully … | Jul 22, 2026 |
| CVE-2026-16624 | UNKNOWN | — | Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then … | Jul 22, 2026 |
| CVE-2026-65650 | MEDIUM | 4.3 | Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload. | Jul 22, 2026 |
| CVE-2026-64835 | HIGH | 8.8 | FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds … | Jul 22, 2026 |
| CVE-2026-64834 | HIGH | 7.5 | FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service … | Jul 22, 2026 |
| CVE-2026-64833 | HIGH | 7.1 | FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying … | Jul 22, 2026 |
| CVE-2026-64832 | HIGH | 8.8 | FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by … | Jul 22, 2026 |
| CVE-2026-16157 | UNKNOWN | — | Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Installing the software outside of the Program Files directory, or on … | Jul 22, 2026 |
| CVE-2026-7328 | UNKNOWN | — | Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode allows a privileged local attacker to cause a denial of service … | Jul 22, 2026 |
| CVE-2026-65013 | HIGH | 8.8 | Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources … | Jul 22, 2026 |
| CVE-2026-65012 | MEDIUM | 5.3 | InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_folder endpoint that accepts attacker-controlled scan_path parameters. Unauthenticated attackers can recursively enumerate arbitrary … | Jul 22, 2026 |
| CVE-2026-65011 | MEDIUM | 4.3 | Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint that allows authenticated users to clone any event definition. … | Jul 22, 2026 |
| CVE-2026-64831 | HIGH | 8.8 | FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses … | Jul 22, 2026 |
| CVE-2026-64830 | HIGH | 8.8 | FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by … | Jul 22, 2026 |
| CVE-2026-16615 | MEDIUM | 6.8 | A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number … | Jul 22, 2026 |
| CVE-2026-64828 | MEDIUM | 6.1 | Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary HTML and JavaScript through the order notes field … | Jul 22, 2026 |
| CVE-2026-49499 | HIGH | 8.8 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote … | Jul 22, 2026 |