Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51763
Total
4101
Critical
15352
High
15010
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-12341 | HIGH | 8.8 | This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to improper validation of OAuth … | Jul 20, 2026 |
| CVE-2026-8170 | UNKNOWN | — | The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links outside of … | Jul 20, 2026 |
| CVE-2026-8169 | UNKNOWN | — | ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The challenge value is generated using an insufficiently random source, which … | Jul 20, 2026 |
| CVE-2026-64612 | HIGH | 7.5 | A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the … | Jul 20, 2026 |
| CVE-2026-55639 | MEDIUM | 5.3 | xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Security Data within the Client MCS … | Jul 20, 2026 |
| CVE-2026-55626 | HIGH | 8.0 | xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using the Xvnc backend over UNIX … | Jul 20, 2026 |
| CVE-2026-48812 | HIGH | 7.5 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's attachment download route skips token authentication … | Jul 20, 2026 |
| CVE-2026-46715 | UNKNOWN | — | Flask-Security-Too allows users to add security features to their Flask applicationa. Version 5.8.0's OAuth reauthentication flow can mark a session as fresh after verifying an … | Jul 20, 2026 |
| CVE-2026-45295 | MEDIUM | 6.5 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tracking endpoint `GET /thread/read/{conversation_id}/{thread_id}` allows … | Jul 20, 2026 |
| CVE-2026-44228 | MEDIUM | 5.4 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting (XSS) vulnerability, … | Jul 20, 2026 |
| CVE-2026-44227 | MEDIUM | 6.1 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. … | Jul 20, 2026 |
| CVE-2026-39878 | CRITICAL | 9.3 | Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenticated attacker to execute arbitrary … | Jul 20, 2026 |
| CVE-2026-34239 | UNKNOWN | — | Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax.php path. This endpoint is protected only by `api_protect_course_script(true)`, which means … | Jul 20, 2026 |
| CVE-2026-26483 | MEDIUM | 6.1 | Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. The application fails to properly sanitize user-supplied input … | Jul 20, 2026 |
| CVE-2026-64207 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net/sched: dualpi2: fix GSO backlog accounting When DualPI2 splits a GSO skb into N segments, … | Jul 20, 2026 |
| CVE-2026-64206 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock l2cap_conn_del() takes conn->lock and then calls cancel_work_sync() for … | Jul 20, 2026 |
| CVE-2026-64205 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: i2c: i801: fix hardware state machine corruption in error path A severe livelock and subsequent … | Jul 20, 2026 |
| CVE-2026-64192 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized When CONFIG_BPF_LSM=y is set, BPF inode … | Jul 20, 2026 |
| CVE-2026-64191 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: i2c: stub: Reject I2C block transfers with invalid length The I2C_SMBUS_I2C_BLOCK_DATA case in stub_xfer() uses … | Jul 20, 2026 |
| CVE-2026-64190 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: team: fix NULL pointer dereference in team_xmit during mode change __team_change_mode() clears team->ops with … | Jul 20, 2026 |
| CVE-2026-64189 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix race between dump and ip_set_list resize The release path of ip_set_dump_do() and … | Jul 20, 2026 |
| CVE-2026-64188 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() rmnet_dellink() removes the endpoint from the hash … | Jul 20, 2026 |
| CVE-2026-64187 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: xfs: fail recovery on a committed log item with no regions If the first op … | Jul 20, 2026 |
| CVE-2026-58484 | HIGH | 7.1 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()` reads each backup's `_manifest.json` and trusts the manifest's `path` field. `EnvironmentManager.pruneBackups()` later passes that … | Jul 20, 2026 |
| CVE-2026-58482 | MEDIUM | 5.9 | Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalInbox` (`lib/approval-inbox.ts`). It is the network surface of the human-in-the-loop Approval Gate, which … | Jul 20, 2026 |