Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51713
Total
4098
Critical
15342
High
14990
Medium
CVE ID Severity Score Description Published
CVE-2026-56587 LOW 3.7 HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications. Jul 21, 2026
CVE-2026-56584 LOW 3.7 HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly … Jul 21, 2026
CVE-2026-47122 MEDIUM 4.2 Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `shouldAcceptNewConnection:` only enforces `SUCodeSigningVerifier validateConnection:` before stage 1 completes. … Jul 21, 2026
CVE-2026-46681 UNKNOWN — @nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.0, the _copyProps function in lib/src/object/copy.ts uses for...in to iterate over source object properties without … Jul 21, 2026
CVE-2026-16448 MEDIUM 6.3 A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 … Jul 21, 2026
CVE-2026-15226 HIGH 8.4 A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates generated by the engine … Jul 21, 2026
CVE-2026-11876 MEDIUM 5.0 In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/stack` endpoint (`get_deployed_stack`) lacks proper RBAC authorization checks, allowing any authenticated user to enumerate all deployed stacks across all … Jul 21, 2026
CVE-2024-5300 MEDIUM 5.6 An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd … Jul 21, 2026
CVE-2026-9499 UNKNOWN — An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated (for example, … Jul 21, 2026
CVE-2026-59848 MEDIUM 5.3 A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded … Jul 21, 2026
CVE-2026-59847 MEDIUM 5.9 A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker … Jul 21, 2026
CVE-2026-47121 MEDIUM 6.1 Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `relativePath.pathComponents containsObject:@".."` and rejects writes whose immediate parent directory IS itself … Jul 21, 2026
CVE-2026-16447 HIGH 7.3 A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument Filedata[] leads … Jul 21, 2026
CVE-2025-66390 UNKNOWN — In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registration flow … Jul 21, 2026
CVE-2026-8285 MEDIUM 4.3 Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Excessive Allocation. This issue affects FlexCity: from 5.536.0 through 11052026. Jul 21, 2026
CVE-2026-8284 MEDIUM 6.1 URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data Manipulation. This issue affects FlexCity: from 5.536.0 through 11052026. Jul 21, 2026
CVE-2026-6792 MEDIUM 6.5 Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCity: from 5.536.0 through 11052026. Jul 21, 2026
CVE-2026-59846 LOW 3.9 A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended … Jul 21, 2026
CVE-2026-16445 HIGH 7.5 A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as … Jul 21, 2026
CVE-2026-16412 CRITICAL 9.8 Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with … Jul 21, 2026
CVE-2026-16411 CRITICAL 9.8 Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of … Jul 21, 2026
CVE-2026-16410 UNKNOWN — JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153. Jul 21, 2026
CVE-2026-16409 UNKNOWN — Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153. Jul 21, 2026
CVE-2026-16408 CRITICAL 9.8 Integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153. Jul 21, 2026
CVE-2026-16407 UNKNOWN — Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153. Jul 21, 2026