Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

52066
Total
4132
Critical
15433
High
15137
Medium
CVE ID Severity Score Description Published
CVE-2026-45695 CRITICAL 9.8 Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to 0.23.0, … Jul 16, 2026
CVE-2026-14890 CRITICAL 9.1 SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, … Jul 16, 2026
CVE-2026-12379 UNKNOWN — An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation of the Axivion Dashboard. The login flow did not properly restrict the post-authentication redirect … Jul 16, 2026
CVE-2025-45868 UNKNOWN — LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to manipulate SQL queries via … Jul 16, 2026
CVE-2026-59863 UNKNOWN — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota honored a poisoned .kiota/workspace.json workspace configuration without validating per-client or per-plugin outputPath … Jul 16, 2026
CVE-2026-59862 HIGH 7.5 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Python generator let attacker-controlled enum value descriptions from x-ms-enum.values[].description flow through KiotaBuilder.SetEnumOptions … Jul 16, 2026
CVE-2026-59861 HIGH 7.5 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Ruby generator embedded OpenAPI default fields, property names, and other schema-derived strings … Jul 16, 2026
CVE-2026-59860 UNKNOWN — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.3, Kiota is affected by a code-generation injection vulnerability in the C# XML documentation-comment … Jul 16, 2026
CVE-2026-59859 UNKNOWN — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-derived … Jul 16, 2026
CVE-2026-59237 UNKNOWN — Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Prospero Flow CRM before 5.5.3 allows a remote, authenticated … Jul 16, 2026
CVE-2026-14254 UNKNOWN — A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed through concurrent authentication requests. Parallel login … Jul 16, 2026
CVE-2026-5674 HIGH 8.8 A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio … Jul 16, 2026
CVE-2026-56456 MEDIUM 5.3 HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information regarding its internal file structure and directory … Jul 16, 2026
CVE-2026-56455 MEDIUM 5.3 HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validate input … Jul 16, 2026
CVE-2026-56454 MEDIUM 5.9 HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic … Jul 16, 2026
CVE-2026-56453 MEDIUM 5.5 HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP … Jul 16, 2026
CVE-2026-35145 LOW 3.1 HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its … Jul 16, 2026
CVE-2026-35143 LOW 3.0 HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies generated during authentication, which … Jul 16, 2026
CVE-2026-35142 LOW 2.6 HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could … Jul 16, 2026
CVE-2026-35141 LOW 2.6 HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data … Jul 16, 2026
CVE-2026-35140 LOW 3.0 HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session … Jul 16, 2026
CVE-2026-9494 MEDIUM 5.5 An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During … Jul 16, 2026
CVE-2026-63306 HIGH 8.6 stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or … Jul 16, 2026
CVE-2026-63305 HIGH 8.1 AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without … Jul 16, 2026
CVE-2026-63304 HIGH 8.1 AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside single quotes without escaping. Attackers … Jul 16, 2026