Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51713
Total
4098
Critical
15342
High
14990
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-15957 | HIGH | 7.5 | Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust … | Jul 21, 2026 |
| CVE-2026-64877 | HIGH | 8.4 | An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database. | Jul 21, 2026 |
| CVE-2026-63454 | HIGH | 7.2 | An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location … | Jul 21, 2026 |
| CVE-2026-63453 | HIGH | 7.2 | Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execute arbitrary … | Jul 21, 2026 |
| CVE-2026-59142 | UNKNOWN | — | Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The attach-time validator shm_validate_header checks the … | Jul 21, 2026 |
| CVE-2026-59141 | UNKNOWN | — | Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked. The attach-time validator rdx_validate_header checks the header … | Jul 21, 2026 |
| CVE-2026-59140 | UNKNOWN | — | Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. The attach-time validator ss_validate_header … | Jul 21, 2026 |
| CVE-2026-59139 | UNKNOWN | — | Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked. The attach-time validator reqrep_validate_header checks the … | Jul 21, 2026 |
| CVE-2026-55084 | HIGH | 8.8 | DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL injection vulnerability was identified in the SqlView API endpoint … | Jul 21, 2026 |
| CVE-2026-55082 | UNKNOWN | — | DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. DHIS2 SQL View data endpoints allowed authenticated users with SQL View … | Jul 21, 2026 |
| CVE-2026-55081 | UNKNOWN | — | DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. The DHIS2 OpenAPI HTML endpoint reflected values from the `scope` query … | Jul 21, 2026 |
| CVE-2026-16441 | UNKNOWN | — | In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, execution is incorrectly … | Jul 21, 2026 |
| CVE-2026-12548 | MEDIUM | 4.2 | A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause … | Jul 21, 2026 |
| CVE-2026-12547 | LOW | 3.4 | SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached … | Jul 21, 2026 |
| CVE-2016-20096 | CRITICAL | 9.8 | Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the … | Jul 21, 2026 |
| CVE-2026-56583 | LOW | 3.1 | HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse. | Jul 21, 2026 |
| CVE-2026-56582 | LOW | 3.1 | HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitive information through a TLS/SSL padding oracle attack. | Jul 21, 2026 |
| CVE-2026-56581 | LOW | 2.6 | HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens. | Jul 21, 2026 |
| CVE-2026-56580 | LOW | 2.2 | HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit publicly disclosed weaknesses and compromise … | Jul 21, 2026 |
| CVE-2026-56579 | LOW | 3.1 | HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed information and compromise the application's security. | Jul 21, 2026 |
| CVE-2026-56578 | LOW | 2.2 | HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities affecting the disclosed software versions. | Jul 21, 2026 |
| CVE-2026-56577 | LOW | 3.1 | HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks. | Jul 21, 2026 |
| CVE-2026-47657 | UNKNOWN | — | HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management controller allowed any … | Jul 21, 2026 |
| CVE-2026-47425 | UNKNOWN | — | Rattler is a library that provides common functionality used within the conda ecosystem. Prior to version 0.43.2, `EntryPoint::FromStr` in `rattler_conda_types` performs only `.trim()` on the … | Jul 21, 2026 |
| CVE-2026-47419 | HIGH | 8.3 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an* Insecure Direct Object Reference. The agent CRUD … | Jul 21, 2026 |