Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51713
Total
4098
Critical
15342
High
14990
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-16356 | UNKNOWN | — | Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | Jul 21, 2026 |
| CVE-2026-16355 | UNKNOWN | — | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | Jul 21, 2026 |
| CVE-2026-16354 | UNKNOWN | — | Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | Jul 21, 2026 |
| CVE-2026-16353 | UNKNOWN | — | Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | Jul 21, 2026 |
| CVE-2026-16352 | UNKNOWN | — | Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | Jul 21, 2026 |
| CVE-2026-16351 | UNKNOWN | — | Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | Jul 21, 2026 |
| CVE-2026-16350 | UNKNOWN | — | Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | Jul 21, 2026 |
| CVE-2026-16349 | UNKNOWN | — | Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. | Jul 21, 2026 |
| CVE-2026-65009 | MEDIUM | 4.3 | OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint that fails to filter operational logs by realm. Attackers with the … | Jul 21, 2026 |
| CVE-2026-65008 | CRITICAL | 9.8 | Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to … | Jul 21, 2026 |
| CVE-2026-65007 | CRITICAL | 9.6 | The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the … | Jul 21, 2026 |
| CVE-2026-64628 | MEDIUM | 5.4 | Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection scan only matches payloads containing literal angle brackets, allowing shortcode … | Jul 21, 2026 |
| CVE-2026-64627 | UNKNOWN | — | Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerability. When the GraphQL API is mounted with public introspection … | Jul 21, 2026 |
| CVE-2026-60080 | UNKNOWN | — | Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload … | Jul 21, 2026 |
| CVE-2026-59845 | MEDIUM | 5.3 | A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may … | Jul 21, 2026 |
| CVE-2026-59844 | MEDIUM | 6.5 | A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to … | Jul 21, 2026 |
| CVE-2026-59843 | MEDIUM | 6.5 | A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop … | Jul 21, 2026 |
| CVE-2026-59842 | LOW | 3.7 | A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper … | Jul 21, 2026 |
| CVE-2026-1617 | CRITICAL | 9.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama allows SQL Injection. This … | Jul 21, 2026 |
| CVE-2026-16461 | MEDIUM | 6.5 | A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), version numbers from a remote RPCBPROC_DUMP reply … | Jul 21, 2026 |
| CVE-2026-64606 | CRITICAL | 9.8 | Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue … | Jul 21, 2026 |
| CVE-2026-64609 | CRITICAL | 9.1 | Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy … | Jul 21, 2026 |
| CVE-2026-64608 | CRITICAL | 9.8 | Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate … | Jul 21, 2026 |
| CVE-2026-62415 | CRITICAL | 9.1 | The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets. | Jul 21, 2026 |
| CVE-2026-1771 | HIGH | 7.2 | The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all versions up … | Jul 21, 2026 |