Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52113
Total
4140
Critical
15446
High
15158
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-58552 | MEDIUM | 5.1 | Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Jul 15, 2026 |
| CVE-2026-58551 | MEDIUM | 5.1 | Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Jul 15, 2026 |
| CVE-2026-58550 | MEDIUM | 4.0 | Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Jul 15, 2026 |
| CVE-2026-58549 | MEDIUM | 4.0 | Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Jul 15, 2026 |
| CVE-2026-46459 | UNKNOWN | — | ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endpoints. This allows an unauthenticated remote attacker to read full facility … | Jul 15, 2026 |
| CVE-2026-46458 | UNKNOWN | — | ICU Scandinavia Boomerang is vulnerable to an information disclosure flaw where sensitive credential files are exposed via static HTTP. This allows an unauthenticated remote attacker … | Jul 15, 2026 |
| CVE-2026-15809 | HIGH | 7.8 | A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting … | Jul 15, 2026 |
| CVE-2026-15779 | MEDIUM | 6.1 | A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a … | Jul 15, 2026 |
| CVE-2026-61873 | HIGH | 8.1 | Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, which is validated against path traversal before Twig processing but … | Jul 15, 2026 |
| CVE-2026-61872 | LOW | 2.5 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the TIFF encoder when an invalid tiff:tile-geometry is specified. Supplying malformed tile geometry parameters causes … | Jul 15, 2026 |
| CVE-2026-61871 | LOW | 3.7 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file … | Jul 15, 2026 |
| CVE-2026-61869 | LOW | 2.9 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing, which … | Jul 15, 2026 |
| CVE-2026-61868 | LOW | 3.7 | ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when opening of the blob fails. Repeated triggering … | Jul 15, 2026 |
| CVE-2026-61867 | LOW | 2.9 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attackers can trigger allocation failures during TIFF image processing … | Jul 15, 2026 |
| CVE-2026-61866 | LOW | 2.9 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by … | Jul 15, 2026 |
| CVE-2026-61865 | LOW | 2.9 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the hough lines operation: when a specific operation fails, a small memory leak occurs. | Jul 15, 2026 |
| CVE-2026-61864 | LOW | 2.9 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in color transformation to the log colorspace: when the operation fails, a small amount of memory … | Jul 15, 2026 |
| CVE-2026-61863 | LOW | 2.9 | ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory leak in the TIFF encoder that occurs when a temporary file cannot be created, resulting … | Jul 15, 2026 |
| CVE-2026-61862 | LOW | 2.9 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not … | Jul 15, 2026 |
| CVE-2026-61860 | LOW | 3.7 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vulnerability that occurs when freetype initialization fails: the method does not exit and continues to use memory … | Jul 15, 2026 |
| CVE-2026-61859 | LOW | 3.3 | ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading … | Jul 15, 2026 |
| CVE-2026-61464 | LOW | 1.8 | ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can … | Jul 15, 2026 |
| CVE-2026-61457 | HIGH | 8.8 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media controller. HandlesMediaUploads::validateFileExtension() inspects only the final file extension … | Jul 15, 2026 |
| CVE-2026-61453 | MEDIUM | 6.1 | Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detectXss()) runs on raw page content before Twig processing. When Twig … | Jul 15, 2026 |
| CVE-2026-61452 | MEDIUM | 5.3 | The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT access tokens are issued without a jti (JWT ID) claim … | Jul 15, 2026 |