Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51943
Total
4127
Critical
15407
High
15098
Medium
CVE ID Severity Score Description Published
CVE-2026-33754 MEDIUM 6.5 Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.9.0 and above, prior to 4.14.5, a remote … Jul 17, 2026
CVE-2026-33434 MEDIUM 4.3 Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and above, prior to 4.14.5, a logic … Jul 17, 2026
CVE-2026-44453 HIGH 7.5 h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack … Jul 16, 2026
CVE-2026-44452 MEDIUM 5.9 h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or … Jul 16, 2026
CVE-2026-44436 HIGH 7.5 Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, Quicly is vulnerable to a … Jul 16, 2026
CVE-2026-44435 HIGH 7.5 Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 937d0e9, an assertion failure is raised … Jul 16, 2026
CVE-2026-44434 MEDIUM 5.3 Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit dccf5d4, Quicly was vulnerable to stateless … Jul 16, 2026
CVE-2026-44433 MEDIUM 5.3 Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, an adversarial peer could send … Jul 16, 2026
CVE-2026-44182 UNKNOWN — Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions prior to 3.3.0, the server … Jul 16, 2026
CVE-2026-44181 UNKNOWN — Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions 2.0.0rc2 and above, prior to … Jul 16, 2026
CVE-2026-43978 HIGH 8.1 wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their session to any higher-privileged account … Jul 16, 2026
CVE-2026-43977 HIGH 7.5 wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read another user's private workout session notes, … Jul 16, 2026
CVE-2026-15997 UNKNOWN — Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffers. This vulnerability is associated with program files https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/shake.C, … Jul 16, 2026
CVE-2026-14253 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Jul 16, 2026
CVE-2026-11740 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Jul 16, 2026
CVE-2026-62826 MEDIUM 4.6 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Jul 16, 2026
CVE-2026-59117 HIGH 7.5 Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network. Jul 16, 2026
CVE-2026-58643 MEDIUM 6.1 Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network. Jul 16, 2026
CVE-2026-58598 HIGH 7.0 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally. Jul 16, 2026
CVE-2026-57077 HIGH 7.7 YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In the bundled libsyck newline_len and is_newline dereference … Jul 16, 2026
CVE-2026-57076 HIGH 7.8 YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor. In the bundled libsyck … Jul 16, 2026
CVE-2026-57075 CRITICAL 9.1 YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec. The base64 decoder in the bundled libsyck indexes … Jul 16, 2026
CVE-2026-53412 CRITICAL 9.8 Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user … Jul 16, 2026
CVE-2026-53411 HIGH 7.8 A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user … Jul 16, 2026
CVE-2026-45368 UNKNOWN — Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for the KirbyTags and image blocks components … Jul 16, 2026