Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51763
Total
4101
Critical
15352
High
15010
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-63729 | MEDIUM | 6.6 | The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers … | Jul 21, 2026 |
| CVE-2026-16334 | MEDIUM | 6.3 | A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder.php. Such manipulation of the argument editid … | Jul 21, 2026 |
| CVE-2026-16332 | HIGH | 7.3 | A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results … | Jul 21, 2026 |
| CVE-2026-16331 | HIGH | 7.3 | A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious … | Jul 21, 2026 |
| CVE-2026-16330 | HIGH | 7.3 | A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument … | Jul 21, 2026 |
| CVE-2026-16329 | HIGH | 7.3 | A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads … | Jul 21, 2026 |
| CVE-2026-63728 | MEDIUM | 6.3 | Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and … | Jul 21, 2026 |
| CVE-2026-55833 | HIGH | 7.5 | Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed … | Jul 21, 2026 |
| CVE-2026-55831 | HIGH | 7.5 | Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared … | Jul 21, 2026 |
| CVE-2026-16327 | HIGH | 7.3 | A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File … | Jul 21, 2026 |
| CVE-2026-15905 | HIGH | 7.8 | Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. (Chromium … | Jul 20, 2026 |
| CVE-2026-15904 | UNKNOWN | — | Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific … | Jul 20, 2026 |
| CVE-2026-15903 | UNKNOWN | — | Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox … | Jul 20, 2026 |
| CVE-2026-15902 | UNKNOWN | — | Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted … | Jul 20, 2026 |
| CVE-2026-15901 | UNKNOWN | — | Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. … | Jul 20, 2026 |
| CVE-2026-15900 | UNKNOWN | — | Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a … | Jul 20, 2026 |
| CVE-2026-15899 | UNKNOWN | — | Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a … | Jul 20, 2026 |
| CVE-2026-64626 | MEDIUM | 6.4 | AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback … | Jul 20, 2026 |
| CVE-2026-64625 | CRITICAL | 9.8 | AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. … | Jul 20, 2026 |
| CVE-2026-64624 | HIGH | 7.8 | FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. … | Jul 20, 2026 |
| CVE-2026-57852 | MEDIUM | 5.6 | Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured scheduled jobs by exploiting a short-circuit logic flaw … | Jul 20, 2026 |
| CVE-2026-57495 | UNKNOWN | — | AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to version 0.1.33, @agenticmail/core prior to version … | Jul 20, 2026 |
| CVE-2026-57494 | UNKNOWN | — | AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated AgenticMail agent can enumerate another agent's … | Jul 20, 2026 |
| CVE-2026-55550 | HIGH | 7.1 | NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal application server actions restrict product creation, update, … | Jul 20, 2026 |
| CVE-2026-55544 | HIGH | 7.6 | NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write operations over the network using … | Jul 20, 2026 |