Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51667
Total
4097
Critical
15338
High
14987
Medium
CVE ID Severity Score Description Published
CVE-2026-46738 CRITICAL 9.1 Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access … Jul 22, 2026
CVE-2026-46737 MEDIUM 6.7 Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access … Jul 22, 2026
CVE-2026-44276 MEDIUM 6.0 Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the REST API. A high … Jul 22, 2026
CVE-2026-40714 HIGH 7.2 Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attacker with remote access could potentially exploit this … Jul 22, 2026
CVE-2026-40712 CRITICAL 9.1 Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access … Jul 22, 2026
CVE-2026-16607 HIGH 7.8 A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for local privilege escalation to root of an … Jul 22, 2026
CVE-2026-16606 CRITICAL 9.8 A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on … Jul 22, 2026
CVE-2026-16552 MEDIUM 6.3 A flaw was found in systemd-tmpfiles. When processing a tmpfiles.d configuration entry that writes to a file, systemd-tmpfiles can follow a symbolic link placed by … Jul 22, 2026
CVE-2026-48029 HIGH 7.1 libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate … Jul 22, 2026
CVE-2026-2395 CRITICAL 9.8 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection. … Jul 22, 2026
CVE-2026-14985 UNKNOWN — The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper … Jul 22, 2026
CVE-2026-13321 HIGH 8.6 The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 … Jul 22, 2026
CVE-2026-13204 HIGH 7.5 If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one … Jul 22, 2026
CVE-2026-12617 HIGH 7.5 The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if … Jul 22, 2026
CVE-2026-11721 HIGH 7.5 It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone … Jul 22, 2026
CVE-2026-11622 HIGH 7.5 A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker needs to … Jul 22, 2026
CVE-2026-11605 HIGH 7.5 The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not … Jul 22, 2026
CVE-2026-11331 HIGH 7.5 An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG … Jul 22, 2026
CVE-2026-10822 MEDIUM 6.5 If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND … Jul 22, 2026
CVE-2026-10723 MEDIUM 6.8 BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions … Jul 22, 2026
CVE-2026-62145 HIGH 7.5 A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges. Jul 22, 2026
CVE-2026-62144 CRITICAL 9.1 An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management … Jul 22, 2026
CVE-2026-56444 MEDIUM 5.9 In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to … Jul 22, 2026
CVE-2026-56416 MEDIUM 4.8 In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes … Jul 22, 2026
CVE-2026-55991 MEDIUM 5.9 In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and … Jul 22, 2026