Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52113
Total
4140
Critical
15446
High
15158
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-49445 | CRITICAL | 9.2 | Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 functionality is enabled, the embedded or standalone Envoy … | Jul 15, 2026 |
| CVE-2026-46684 | UNKNOWN | — | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() pass X-DE-TOKEN values to TokenUtils.validate(), … | Jul 15, 2026 |
| CVE-2026-45738 | HIGH | 7.3 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD users with application write access can … | Jul 15, 2026 |
| CVE-2026-45737 | MEDIUM | 6.3 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expose Kubernetes Secret … | Jul 15, 2026 |
| CVE-2026-45535 | UNKNOWN | — | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL-type datasets store attacker-controlled SQL variable defaultValue entries such as ${var} … | Jul 15, 2026 |
| CVE-2026-45534 | UNKNOWN | — | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-controlled rsjdbc.ini configuration from System.getProperty("java.io.tmpdir"), setting … | Jul 15, 2026 |
| CVE-2026-45533 | UNKNOWN | — | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase export-center deletion can accept path traversal sequences such as ../ in … | Jul 15, 2026 |
| CVE-2026-45419 | UNKNOWN | — | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template saves call TemplateManageService#save, StaticResourceServer#saveFilesToServe, and the /de2api/templateManage/save endpoint with attacker-controlled … | Jul 15, 2026 |
| CVE-2026-45417 | UNKNOWN | — | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase datasource connection status checks concatenate configuration.getSchema() into getTablesSql and execute the … | Jul 15, 2026 |
| CVE-2026-45320 | UNKNOWN | — | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase dashboard SQL variables such as ${deptId} are processed by SqlparserUtils.transFilter(), whose … | Jul 15, 2026 |
| CVE-2026-40958 | LOW | 3.7 | CVE-2026-40958 is a input validation error in Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol … | Jul 15, 2026 |
| CVE-2026-40957 | HIGH | 7.5 | o CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers with control of a malicious web site … | Jul 15, 2026 |
| CVE-2026-40956 | LOW | 3.7 | CVE-2026-40956 is a memory disclosure vulnerability in Secure Access client versions prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel … | Jul 15, 2026 |
| CVE-2026-40955 | LOW | 3.7 | CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total … | Jul 15, 2026 |
| CVE-2026-40954 | LOW | 3.7 | CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total … | Jul 15, 2026 |
| CVE-2026-40953 | MEDIUM | 4.4 | CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can … | Jul 15, 2026 |
| CVE-2026-40952 | HIGH | 7.8 | CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to … | Jul 15, 2026 |
| CVE-2026-33443 | MEDIUM | 5.9 | CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel … | Jul 15, 2026 |
| CVE-2026-62947 | MEDIUM | 4.9 | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus … | Jul 15, 2026 |
| CVE-2026-62355 | MEDIUM | 5.4 | TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine Cloud DB … | Jul 15, 2026 |
| CVE-2026-62353 | MEDIUM | 5.4 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailing backslash in a SQL string … | Jul 15, 2026 |
| CVE-2026-62351 | HIGH | 7.5 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/src/transComm.c transDecompressMsg() read STransCompMsg.contLen when pHead->comp == 1 without first validating … | Jul 15, 2026 |
| CVE-2026-62350 | HIGH | 7.2 | TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user with create udf privilege could upload a … | Jul 15, 2026 |
| CVE-2026-62349 | HIGH | 8.3 | TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, source/libs/parser/src/parUtil.c trimString() checks space for only one byte … | Jul 15, 2026 |
| CVE-2026-62348 | MEDIUM | 5.4 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allowed an authenticated low-privilege SQL user to run KILL … | Jul 15, 2026 |