Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

52341
Total
4150
Critical
15505
High
15208
Medium
CVE ID Severity Score Description Published
CVE-2026-58477 HIGH 8.2 Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauthenticated attackers to overwrite sensitive configuration settings by supplying arbitrary parameter … Jul 14, 2026
CVE-2026-58476 HIGH 8.1 Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing administrative actions by luring a … Jul 14, 2026
CVE-2026-58475 MEDIUM 6.1 Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by supplying malicious script … Jul 14, 2026
CVE-2026-52837 UNKNOWN — Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule view at `/index.php/booking/reschedule/{appointment_hash}` (handled by `Booking::index()`) embeds the … Jul 14, 2026
CVE-2026-51105 HIGH 7.5 Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a remote attacker to cause a denial of service via the OP_SERVERMESSAGE Handler. Jul 14, 2026
CVE-2026-15736 HIGH 8.3 Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of user-supplied column identifiers in merge operations could allow SQL injection through … Jul 14, 2026
CVE-2026-15696 HIGH 8.8 A vulnerability has been found in Tenda BE12 Pro 16.03.66.23. The impacted element is the function fromVirtualSer of the file /goform/VirtualSer. Such manipulation of the … Jul 14, 2026
CVE-2026-15695 HIGH 8.8 A flaw has been found in Tenda BE12 Pro 16.03.66.23. The affected element is the function fromDhcpListClient of the file /goform/DhcpListClient. This manipulation of the … Jul 14, 2026
CVE-2026-15694 HIGH 8.8 A vulnerability was detected in Tenda BE12 Pro 16.03.66.23. Impacted is the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page results … Jul 14, 2026
CVE-2026-15265 CRITICAL 9.1 A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, … Jul 14, 2026
CVE-2026-14903 HIGH 7.7 Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root. Jul 14, 2026
CVE-2026-14902 MEDIUM 4.0 An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs. Jul 14, 2026
CVE-2026-10714 UNKNOWN — A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from … Jul 14, 2026
CVE-2026-10672 HIGH 8.2 subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri, size CONFIG_LWM2M_SWMGMT_PACKAGE_URI_LEN, default 128) with memcpy(context.uri, uri, LWM2M_PACKAGE_URI_LEN), copying exactly the destination size … Jul 14, 2026
CVE-2026-10671 HIGH 7.1 In Zephyr's kernel pipe implementation, the userspace syscall verifier z_vrfy_k_pipe_init() in kernel/pipe.c used K_SYSCALL_OBJ() (which requires the kernel object to already be initialized) instead of … Jul 14, 2026
CVE-2026-10670 MEDIUM 5.5 The CONFIG_USERSPACE verification handler for the k_thread_name_copy() system call (z_vrfy_k_thread_name_copy() in kernel/thread.c) calls k_object_find() on the caller-supplied thread pointer and then dereferences the returned struct … Jul 14, 2026
CVE-2026-10669 HIGH 7.8 On Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_validate() in arch/xtensa/core/mpu.c — the architecture hook that verifies a user-mode-supplied buffer is accessible to the calling … Jul 14, 2026
CVE-2026-10573 UNKNOWN — A denial-of-service security issue exists in 1734 POINT I/O™ module. The security issue stems from improper handling of crafted CIP messages, which can cause the … Jul 14, 2026
CVE-2025-12012 UNKNOWN — A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the … Jul 14, 2026
CVE-2025-12011 UNKNOWN — A denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter … Jul 14, 2026
CVE-2026-53566 UNKNOWN — Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20. Jul 14, 2026
CVE-2026-15693 HIGH 8.8 A security vulnerability has been detected in Tenda BE12 Pro 16.03.66.23. This issue affects the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the … Jul 14, 2026
CVE-2026-8314 UNKNOWN — A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. The vulnerability stems from improper validation of … Jul 14, 2026
CVE-2026-8313 UNKNOWN — A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of … Jul 14, 2026
CVE-2026-8312 UNKNOWN — A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of … Jul 14, 2026