Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52066
Total
4132
Critical
15433
High
15137
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-45695 | CRITICAL | 9.8 | Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to 0.23.0, … | Jul 16, 2026 |
| CVE-2026-14890 | CRITICAL | 9.1 | SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, … | Jul 16, 2026 |
| CVE-2026-12379 | UNKNOWN | — | An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation of the Axivion Dashboard. The login flow did not properly restrict the post-authentication redirect … | Jul 16, 2026 |
| CVE-2025-45868 | UNKNOWN | — | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to manipulate SQL queries via … | Jul 16, 2026 |
| CVE-2026-59863 | UNKNOWN | — | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota honored a poisoned .kiota/workspace.json workspace configuration without validating per-client or per-plugin outputPath … | Jul 16, 2026 |
| CVE-2026-59862 | HIGH | 7.5 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Python generator let attacker-controlled enum value descriptions from x-ms-enum.values[].description flow through KiotaBuilder.SetEnumOptions … | Jul 16, 2026 |
| CVE-2026-59861 | HIGH | 7.5 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Ruby generator embedded OpenAPI default fields, property names, and other schema-derived strings … | Jul 16, 2026 |
| CVE-2026-59860 | UNKNOWN | — | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.3, Kiota is affected by a code-generation injection vulnerability in the C# XML documentation-comment … | Jul 16, 2026 |
| CVE-2026-59859 | UNKNOWN | — | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-derived … | Jul 16, 2026 |
| CVE-2026-59237 | UNKNOWN | — | Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Prospero Flow CRM before 5.5.3 allows a remote, authenticated … | Jul 16, 2026 |
| CVE-2026-14254 | UNKNOWN | — | A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed through concurrent authentication requests. Parallel login … | Jul 16, 2026 |
| CVE-2026-5674 | HIGH | 8.8 | A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio … | Jul 16, 2026 |
| CVE-2026-56456 | MEDIUM | 5.3 | HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information regarding its internal file structure and directory … | Jul 16, 2026 |
| CVE-2026-56455 | MEDIUM | 5.3 | HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validate input … | Jul 16, 2026 |
| CVE-2026-56454 | MEDIUM | 5.9 | HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic … | Jul 16, 2026 |
| CVE-2026-56453 | MEDIUM | 5.5 | HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP … | Jul 16, 2026 |
| CVE-2026-35145 | LOW | 3.1 | HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its … | Jul 16, 2026 |
| CVE-2026-35143 | LOW | 3.0 | HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies generated during authentication, which … | Jul 16, 2026 |
| CVE-2026-35142 | LOW | 2.6 | HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could … | Jul 16, 2026 |
| CVE-2026-35141 | LOW | 2.6 | HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data … | Jul 16, 2026 |
| CVE-2026-35140 | LOW | 3.0 | HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session … | Jul 16, 2026 |
| CVE-2026-9494 | MEDIUM | 5.5 | An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During … | Jul 16, 2026 |
| CVE-2026-63306 | HIGH | 8.6 | stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or … | Jul 16, 2026 |
| CVE-2026-63305 | HIGH | 8.1 | AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without … | Jul 16, 2026 |
| CVE-2026-63304 | HIGH | 8.1 | AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside single quotes without escaping. Attackers … | Jul 16, 2026 |