Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52566
Total
4174
Critical
15576
High
15266
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-8085 | UNKNOWN | — | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of … | Jul 14, 2026 |
| CVE-2026-62393 | MEDIUM | 4.3 | Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized … | Jul 14, 2026 |
| CVE-2026-62392 | CRITICAL | 9.8 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters … | Jul 14, 2026 |
| CVE-2026-62390 | CRITICAL | 9.8 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the … | Jul 14, 2026 |
| CVE-2026-53565 | UNKNOWN | — | Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows. This issue affects Secure Access Client for … | Jul 14, 2026 |
| CVE-2026-49488 | MEDIUM | 6.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. An … | Jul 14, 2026 |
| CVE-2026-15719 | MEDIUM | 5.4 | We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This … | Jul 14, 2026 |
| CVE-2026-15718 | MEDIUM | 4.3 | We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This … | Jul 14, 2026 |
| CVE-2026-15692 | HIGH | 8.8 | A weakness has been identified in Tenda BE12 Pro 16.03.66.23. This vulnerability affects the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Executing a manipulation of the … | Jul 14, 2026 |
| CVE-2026-15691 | HIGH | 8.8 | A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. This affects the function fromSafeClientFilter of the file /goform/SafeClientFilter. Performing a manipulation of the … | Jul 14, 2026 |
| CVE-2026-15305 | UNKNOWN | — | Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowedMimeTypes configured. The restriction was not enforced … | Jul 14, 2026 |
| CVE-2026-12588 | UNKNOWN | — | An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger … | Jul 14, 2026 |
| CVE-2026-10577 | UNKNOWN | — | A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing … | Jul 14, 2026 |
| CVE-2026-9341 | MEDIUM | 4.3 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up … | Jul 14, 2026 |
| CVE-2026-15690 | LOW | 3.1 | A vulnerability was identified in open62541 up to 1.5.5. Affected by this issue is the function responseReadNamespacesArray of the file src/client/ua_client_connect.c of the component Shared … | Jul 14, 2026 |
| CVE-2026-62422 | CRITICAL | 10.0 | In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible | Jul 14, 2026 |
| CVE-2026-15389 | UNKNOWN | — | A vulnerability relating to insufficient access control has been identified in the session management of the Sesame Time web application and its REST v3 API. … | Jul 14, 2026 |
| CVE-2026-58319 | CRITICAL | 9.1 | Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could … | Jul 14, 2026 |
| CVE-2026-56451 | CRITICAL | 10.0 | A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web … | Jul 14, 2026 |
| CVE-2026-54429 | HIGH | 7.4 | A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handle high-volume multicast network traffic, which can exhaust available … | Jul 14, 2026 |
| CVE-2026-3014 | CRITICAL | 9.1 | Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API. The vulnerability causes users … | Jul 14, 2026 |
| CVE-2026-15043 | CRITICAL | 9.8 | DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates … | Jul 14, 2026 |
| CVE-2026-14852 | UNKNOWN | — | Privilege escalation in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows a local unprivileged user to execute arbitrary … | Jul 14, 2026 |
| CVE-2026-12478 | MEDIUM | 4.8 | The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A malicious … | Jul 14, 2026 |
| CVE-2025-40945 | MEDIUM | 6.7 | A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All versions < V2512.7000), Simcenter … | Jul 14, 2026 |