Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51713
Total
4098
Critical
15342
High
14990
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-64616 | UNKNOWN | — | Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ndarray.h … | Jul 21, 2026 |
| CVE-2026-64615 | UNKNOWN | — | Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in graph.h … | Jul 21, 2026 |
| CVE-2026-64614 | UNKNOWN | — | Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in deque.h … | Jul 21, 2026 |
| CVE-2026-64613 | UNKNOWN | — | Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOW. The segment is created in buf_generic.h with open(path, … | Jul 21, 2026 |
| CVE-2026-59147 | UNKNOWN | — | Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find. The attach-time validator dsu_validate_header checks the header … | Jul 21, 2026 |
| CVE-2026-59146 | UNKNOWN | — | Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph_walk_cell and sph_alloc_slot. The attach-time validator … | Jul 21, 2026 |
| CVE-2026-59145 | UNKNOWN | — | Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find. The attach-time validator si_validate_header is thorough … | Jul 21, 2026 |
| CVE-2026-59144 | UNKNOWN | — | Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time validator ring_validate_header checks the capacity-overflow and … | Jul 21, 2026 |
| CVE-2026-59143 | UNKNOWN | — | Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_contains_locked. The attach-time validator rb_validate_header checks the … | Jul 21, 2026 |
| CVE-2026-56852 | UNKNOWN | — | A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. | Jul 21, 2026 |
| CVE-2026-56146 | MEDIUM | 5.4 | Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with … | Jul 21, 2026 |
| CVE-2026-56145 | MEDIUM | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL … | Jul 21, 2026 |
| CVE-2026-56144 | MEDIUM | 5.3 | Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By … | Jul 21, 2026 |
| CVE-2026-50759 | UNKNOWN | — | An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instance/{instance_id} endpoints with no authentication. | Jul 21, 2026 |
| CVE-2026-50758 | UNKNOWN | — | Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter | Jul 21, 2026 |
| CVE-2026-50757 | UNKNOWN | — | Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server | Jul 21, 2026 |
| CVE-2026-50756 | UNKNOWN | — | An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component | Jul 21, 2026 |
| CVE-2026-50755 | UNKNOWN | — | An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value | Jul 21, 2026 |
| CVE-2026-49092 | MEDIUM | 4.3 | Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under … | Jul 21, 2026 |
| CVE-2026-47671 | MEDIUM | 5.4 | Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost configserver` used by `nhost dev` … | Jul 21, 2026 |
| CVE-2026-47667 | HIGH | 7.5 | CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field is read as an `unsigned int` from … | Jul 21, 2026 |
| CVE-2026-46600 | UNKNOWN | — | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. | Jul 21, 2026 |
| CVE-2026-46403 | MEDIUM | 6.3 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithTypedArguments` as a read-only execution mechanism. The hook saves the … | Jul 21, 2026 |
| CVE-2026-42397 | MEDIUM | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can … | Jul 21, 2026 |
| CVE-2026-30632 | UNKNOWN | — | Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool. | Jul 21, 2026 |