Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51713
Total
4098
Critical
15342
High
14990
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-47143 | MEDIUM | 5.1 | Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F … | Jul 21, 2026 |
| CVE-2026-46556 | MEDIUM | 6.5 | FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Request Forgery (SSRF) vulnerability in get_image_info() … | Jul 21, 2026 |
| CVE-2026-45383 | UNKNOWN | — | libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a heap buffer overflow (out-of-bounds READ) exists in `decoder_context::decode_slice_unit_WPP()` … | Jul 21, 2026 |
| CVE-2026-45382 | UNKNOWN | — | libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decoder_context::decode_slice_unit_tiles` (libde265/decctx.cc:920) reads `pps.CtbAddrRStoTS[ctbAddrRS]` at line 966 where `ctbAddrRS = … | Jul 21, 2026 |
| CVE-2026-44879 | HIGH | 7.2 | A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injection on certain CLI … | Jul 21, 2026 |
| CVE-2026-44878 | HIGH | 7.2 | A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successful … | Jul 21, 2026 |
| CVE-2026-30633 | UNKNOWN | — | Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools. | Jul 21, 2026 |
| CVE-2026-30631 | UNKNOWN | — | An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrary code via crafted path to `computer_write_file`. | Jul 21, 2026 |
| CVE-2026-16318 | MEDIUM | 5.3 | The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store the peer's transport parameters. When a TLS 1.3 connection … | Jul 21, 2026 |
| CVE-2026-16317 | MEDIUM | 6.5 | Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently discard individual application data records … | Jul 21, 2026 |
| CVE-2026-12139 | MEDIUM | 4.4 | Tanium addressed an information disclosure vulnerability in Connect. | Jul 21, 2026 |
| CVE-2026-11925 | LOW | 2.7 | Tanium addressed a User Interface (UI) Misrepresentation of Critical Information vulnerability in Tanium Server. | Jul 21, 2026 |
| CVE-2026-65069 | UNKNOWN | — | Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in dsu.h … | Jul 21, 2026 |
| CVE-2026-65068 | UNKNOWN | — | Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sphash.h … | Jul 21, 2026 |
| CVE-2026-65067 | UNKNOWN | — | Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in intern.h … | Jul 21, 2026 |
| CVE-2026-65066 | UNKNOWN | — | Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ring.h … | Jul 21, 2026 |
| CVE-2026-65065 | UNKNOWN | — | Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in roaring.h … | Jul 21, 2026 |
| CVE-2026-65064 | UNKNOWN | — | Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in shm_generic.h … | Jul 21, 2026 |
| CVE-2026-65063 | UNKNOWN | — | Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in radix.h … | Jul 21, 2026 |
| CVE-2026-65062 | UNKNOWN | — | Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sortedset.h … | Jul 21, 2026 |
| CVE-2026-65061 | UNKNOWN | — | Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in reqrep.h … | Jul 21, 2026 |
| CVE-2026-64880 | HIGH | 7.1 | Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized … | Jul 21, 2026 |
| CVE-2026-64879 | CRITICAL | 9.9 | A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and … | Jul 21, 2026 |
| CVE-2026-64878 | CRITICAL | 9.9 | Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via … | Jul 21, 2026 |
| CVE-2026-64617 | UNKNOWN | — | Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in pubsub.h … | Jul 21, 2026 |