Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51763
Total
4101
Critical
15352
High
15010
Medium
CVE ID Severity Score Description Published
CVE-2026-63729 MEDIUM 6.6 The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers … Jul 21, 2026
CVE-2026-16334 MEDIUM 6.3 A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder.php. Such manipulation of the argument editid … Jul 21, 2026
CVE-2026-16332 HIGH 7.3 A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results … Jul 21, 2026
CVE-2026-16331 HIGH 7.3 A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious … Jul 21, 2026
CVE-2026-16330 HIGH 7.3 A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument … Jul 21, 2026
CVE-2026-16329 HIGH 7.3 A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads … Jul 21, 2026
CVE-2026-63728 MEDIUM 6.3 Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and … Jul 21, 2026
CVE-2026-55833 HIGH 7.5 Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed … Jul 21, 2026
CVE-2026-55831 HIGH 7.5 Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared … Jul 21, 2026
CVE-2026-16327 HIGH 7.3 A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File … Jul 21, 2026
CVE-2026-15905 HIGH 7.8 Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. (Chromium … Jul 20, 2026
CVE-2026-15904 UNKNOWN — Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific … Jul 20, 2026
CVE-2026-15903 UNKNOWN — Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox … Jul 20, 2026
CVE-2026-15902 UNKNOWN — Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … Jul 20, 2026
CVE-2026-15901 UNKNOWN — Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. … Jul 20, 2026
CVE-2026-15900 UNKNOWN — Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a … Jul 20, 2026
CVE-2026-15899 UNKNOWN — Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a … Jul 20, 2026
CVE-2026-64626 MEDIUM 6.4 AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback … Jul 20, 2026
CVE-2026-64625 CRITICAL 9.8 AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. … Jul 20, 2026
CVE-2026-64624 HIGH 7.8 FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. … Jul 20, 2026
CVE-2026-57852 MEDIUM 5.6 Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured scheduled jobs by exploiting a short-circuit logic flaw … Jul 20, 2026
CVE-2026-57495 UNKNOWN — AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to version 0.1.33, @agenticmail/core prior to version … Jul 20, 2026
CVE-2026-57494 UNKNOWN — AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated AgenticMail agent can enumerate another agent's … Jul 20, 2026
CVE-2026-55550 HIGH 7.1 NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal application server actions restrict product creation, update, … Jul 20, 2026
CVE-2026-55544 HIGH 7.6 NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write operations over the network using … Jul 20, 2026