Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42275
Total
3446
Critical
12492
High
12441
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-81532 | HIGH | 8.8 | A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name … | Aug 28, 2026 |
| CVE-2026-81520 | HIGH | 7.5 | A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange … | Aug 28, 2026 |
| CVE-2026-81518 | HIGH | 7.5 | When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, … | Aug 28, 2026 |
| CVE-2026-81517 | HIGH | 7.5 | An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust … | Aug 28, 2026 |
| CVE-2026-81490 | HIGH | 7.7 | A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning … | Aug 28, 2026 |
| CVE-2026-77078 | HIGH | 7.5 | multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially crafted text field names can cause an uncaught RangeError … | Aug 28, 2026 |
| CVE-2026-77063 | LOW | 3.7 | multer is a middleware for handling multipart/form-data in Node.js. When an application uses an asynchronous fileFilter together with the fileSize limit, a race condition in … | Aug 28, 2026 |
| CVE-2026-77037 | HIGH | 7.5 | multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is aborted or truncated before the write stream finishes, … | Aug 28, 2026 |
| CVE-2026-76651 | UNKNOWN | — | A buffer overflow vulnerability exists in the embedded HTTP service in TL-WR841N v14 when processing multipart/form-data requests. Insufficient validation of an attacker-controlled boundary parameter may … | Aug 28, 2026 |
| CVE-2026-76650 | UNKNOWN | — | A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP state variable query requests. A specially crafted SOAP query … | Aug 28, 2026 |
| CVE-2026-76649 | UNKNOWN | — | A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP action requests. A specially crafted SOAP action request containing … | Aug 28, 2026 |
| CVE-2026-75118 | UNKNOWN | — | A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.20 due to insufficient bounds checking of encrypted requests to the /cgi/login … | Aug 28, 2026 |
| CVE-2026-55891 | NONE | — | PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, Request::getRequestUri() in lib/Request.php passes $_SERVER['REQUEST_URI'] through FILTER_SANITIZE_URL, which … | Aug 28, 2026 |
| CVE-2026-55763 | UNKNOWN | — | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfer in core/kapp/accounts/accounts.go calls SubFromBalance after the split loop and after the … | Aug 28, 2026 |
| CVE-2026-55696 | MEDIUM | 4.3 | PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, AttachmentViewer.setAttachment in js/privatebin.js uses getAttachmentMimeType to accept attacker-controlled … | Aug 28, 2026 |
| CVE-2026-55678 | UNKNOWN | — | Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering accepts cluster join requests without authentication when cluster.enabled is … | Aug 28, 2026 |
| CVE-2026-51665 | UNKNOWN | — | Incorrect access control in the getTracerouteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain traceroute diagnostic logs via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51664 | UNKNOWN | — | Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Telnet service enablement status information via sending a crafted … | Aug 28, 2026 |
| CVE-2026-51663 | UNKNOWN | — | Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger wireless scans and retrieve AP-client scan results via sending … | Aug 28, 2026 |
| CVE-2026-51662 | UNKNOWN | — | Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware check status information via sending a crafted … | Aug 28, 2026 |
| CVE-2026-51661 | UNKNOWN | — | Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain port-forwarding rules via sending a crafted POST request to … | Aug 28, 2026 |
| CVE-2026-3686 | MEDIUM | 6.2 | IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 is vulnerable to a denial of service due to improper limitation of resources. | Aug 28, 2026 |
| CVE-2026-3627 | CRITICAL | 9.1 | IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to … | Aug 28, 2026 |
| CVE-2026-22056 | UNKNOWN | — | StorageGRID (formerly StorageGRID Webscale) versions 11.5 and higher in a non-standard configuration and scenario are susceptible to a Denial of Service vulnerability. Successful exploit could … | Aug 28, 2026 |
| CVE-2026-19295 | CRITICAL | 9.9 | IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with … | Aug 28, 2026 |