Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51943
Total
4127
Critical
15407
High
15098
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-46420 | MEDIUM | 5.6 | setup-php is a GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and tools. From 2.25.0 prior to 2.37.1, shivammathur/setup-php resolves the … | Jul 17, 2026 |
| CVE-2026-45799 | HIGH | 7.5 | Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArrayProtoReader32.skipGroup() and ProtoReader.skipGroup() in wire-runtime do not validate … | Jul 17, 2026 |
| CVE-2026-45704 | UNKNOWN | — | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses inconsistent authorization between the report listing endpoint … | Jul 17, 2026 |
| CVE-2026-45260 | HIGH | 8.1 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV asset endpoint exposes a MOVE operation through … | Jul 17, 2026 |
| CVE-2026-44974 | UNKNOWN | — | @hapi/content provided HTTP Content-* headers parsing. Prior to 6.0.2, Content.disposition() retained the last occurrence of each duplicate parameter while Content.type() retained the first occurrence of … | Jul 17, 2026 |
| CVE-2026-44739 | HIGH | 8.7 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigAction endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php passes malicious SQL configuration … | Jul 17, 2026 |
| CVE-2026-43636 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Jul 17, 2026 |
| CVE-2026-42168 | UNKNOWN | — | django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. These fields are passed directly to … | Jul 17, 2026 |
| CVE-2026-36669 | UNKNOWN | — | An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the web-accessible … | Jul 17, 2026 |
| CVE-2026-16118 | HIGH | 7.1 | A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled … | Jul 17, 2026 |
| CVE-2026-15995 | MEDIUM | 5.4 | IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain incorrect report summary results or cause report-processing failures … | Jul 17, 2026 |
| CVE-2026-15415 | MEDIUM | 5.5 | AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure required to run bioinformatics analyses at scale for clinical … | Jul 17, 2026 |
| CVE-2026-15322 | HIGH | 7.5 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in … | Jul 17, 2026 |
| CVE-2026-15093 | MEDIUM | 4.3 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious websites due to improper validation of user-supplied … | Jul 17, 2026 |
| CVE-2026-15091 | CRITICAL | 9.3 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web … | Jul 17, 2026 |
| CVE-2026-15069 | MEDIUM | 5.4 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code due to improper neutralization of input during … | Jul 17, 2026 |
| CVE-2026-14979 | MEDIUM | 5.3 | IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and … | Jul 17, 2026 |
| CVE-2026-14971 | LOW | 3.9 | IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized operations under non-default conditions. | Jul 17, 2026 |
| CVE-2026-14501 | MEDIUM | 4.3 | IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain sensitive information due to … | Jul 17, 2026 |
| CVE-2026-14499 | HIGH | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper … | Jul 17, 2026 |
| CVE-2026-13473 | HIGH | 8.1 | IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper … | Jul 17, 2026 |
| CVE-2026-13448 | HIGH | 8.1 | IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The … | Jul 17, 2026 |
| CVE-2026-12283 | MEDIUM | 6.8 | Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a … | Jul 17, 2026 |
| CVE-2025-51678 | UNKNOWN | — | An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to unexpected behavior. | Jul 17, 2026 |
| CVE-2025-51677 | UNKNOWN | — | An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can … | Jul 17, 2026 |