Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51763
Total
4101
Critical
15352
High
15010
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-33328 | UNKNOWN | — | libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.18.0, the `gifload` operation could incorrectly … | Jul 20, 2026 |
| CVE-2026-33327 | UNKNOWN | — | libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions … | Jul 20, 2026 |
| CVE-2026-32825 | HIGH | 7.3 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, … | Jul 20, 2026 |
| CVE-2026-32824 | HIGH | 7.3 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, … | Jul 20, 2026 |
| CVE-2026-32823 | MEDIUM | 4.3 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, … | Jul 20, 2026 |
| CVE-2026-32821 | HIGH | 8.1 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, … | Jul 20, 2026 |
| CVE-2026-32820 | HIGH | 7.5 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, … | Jul 20, 2026 |
| CVE-2026-32819 | MEDIUM | 4.3 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, … | Jul 20, 2026 |
| CVE-2026-32806 | HIGH | 7.5 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, … | Jul 20, 2026 |
| CVE-2026-16312 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Jul 20, 2026 |
| CVE-2026-6793 | MEDIUM | 5.4 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS. This issue affects … | Jul 20, 2026 |
| CVE-2026-63429 | HIGH | 8.6 | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` requirement, … | Jul 20, 2026 |
| CVE-2026-63428 | MEDIUM | 5.8 | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id, name, value}]` array from the submitter and stores it verbatim … | Jul 20, 2026 |
| CVE-2026-63102 | MEDIUM | 5.4 | rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role … | Jul 20, 2026 |
| CVE-2026-51027 | CRITICAL | 9.9 | An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component. | Jul 20, 2026 |
| CVE-2026-51026 | MEDIUM | 6.5 | Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a crafted request. | Jul 20, 2026 |
| CVE-2026-48824 | MEDIUM | 5.3 | Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2026-45710, "Mailpit: Set a default 50MB p/m … | Jul 20, 2026 |
| CVE-2026-46671 | MEDIUM | 4.4 | Rust OneNote File Parser is a parser for Microsoft OneNote files implemented in Rust. Prior to version 1.1.1, a maliciously crafted `.onetoc2` table-of-contents file can … | Jul 20, 2026 |
| CVE-2026-46428 | UNKNOWN | — | lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's `boring-tls` integration silently … | Jul 20, 2026 |
| CVE-2026-46415 | HIGH | 8.2 | The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address. Prior to … | Jul 20, 2026 |
| CVE-2026-46412 | CRITICAL | 10.0 | @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used … | Jul 20, 2026 |
| CVE-2026-45797 | UNKNOWN | — | HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, the `/api/upload` endpoint allows unauthenticated file uploads including SVG files. Uploaded SVGs are stored in … | Jul 20, 2026 |
| CVE-2026-45713 | HIGH | 7.5 | Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that controls … | Jul 20, 2026 |
| CVE-2026-45712 | MEDIUM | 5.9 | Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?data=…) maintains a package-level assets map[string]MessageAssets cache, but … | Jul 20, 2026 |
| CVE-2026-45711 | MEDIUM | 5.9 | Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <out-dir> sub-command downloads every message from … | Jul 20, 2026 |