Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

52566
Total
4174
Critical
15576
High
15266
Medium
CVE ID Severity Score Description Published
CVE-2026-9561 UNKNOWN — Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. … Jul 14, 2026
CVE-2026-8384 MEDIUM 5.3 In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the expected: /admin/secret.txt Jetty itself is … Jul 14, 2026
CVE-2026-6790 MEDIUM 5.3 In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in … Jul 14, 2026
CVE-2026-59246 UNKNOWN — Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP/2 server to exhaust memory on the client host and cause a denial … Jul 14, 2026
CVE-2026-59084 CRITICAL 9.1 Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from … Jul 14, 2026
CVE-2026-59083 CRITICAL 9.1 Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: … Jul 14, 2026
CVE-2026-58229 UNKNOWN — Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client host and cause a denial … Jul 14, 2026
CVE-2026-57898 CRITICAL 9.0 In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the … Jul 14, 2026
CVE-2026-15416 HIGH 8.9 A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access … Jul 14, 2026
CVE-2026-15183 UNKNOWN — Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can allow attackers to exfiltrate OAuth client credentials, execute arbitrary SQL … Jul 14, 2026
CVE-2026-15076 HIGH 7.5 In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Vert.x Web Client does not validate that … Jul 14, 2026
CVE-2026-15075 HIGH 7.5 In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates all request headers as-is across cross-origin HTTP … Jul 14, 2026
CVE-2026-13699 MEDIUM 4.3 In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to validate the existence of the optional data_point field in PublishValueRequest. When a request … Jul 14, 2026
CVE-2026-12606 MEDIUM 5.3 Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request … Jul 14, 2026
CVE-2026-10051 HIGH 7.5 In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection. Subsequent … Jul 14, 2026
CVE-2025-8412 UNKNOWN — A Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in SUSE Virtual Machine Driver Pack allows an attacker with the ability to … Jul 14, 2026
CVE-2024-7708 HIGH 7.5 For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly … Jul 14, 2026
CVE-2026-6851 UNKNOWN — An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and Internet Security on … Jul 14, 2026
CVE-2026-59674 UNKNOWN — A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user to escalate to root. This issue affects openSUSE Tumbleweed: … Jul 14, 2026
CVE-2026-15678 LOW 3.5 A security vulnerability has been detected in code-projects Online Job Portal 1.0. This impacts an unknown function of the file /Admin/DetailJob.php. The manipulation leads to … Jul 14, 2026
CVE-2026-15677 HIGH 7.3 A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the … Jul 14, 2026
CVE-2026-15676 HIGH 7.3 A security flaw has been discovered in code-projects Online Job Portal up to 1.0. The impacted element is an unknown function of the file /Admin/DeleteUser.php. … Jul 14, 2026
CVE-2026-15675 HIGH 7.3 A vulnerability was identified in code-projects Online Job Portal 1.0. The affected element is an unknown function of the file /Admin/EditUser.php. Such manipulation of the … Jul 14, 2026
CVE-2026-15672 MEDIUM 6.3 A vulnerability was determined in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the file /intrams/admin/add_judges.php. This manipulation of the argument fname … Jul 14, 2026
CVE-2026-15669 MEDIUM 5.3 A vulnerability was found in louisho5 picobot up to 0.2.0. This issue affects the function ExecTool.Execute of the file internal/agent/tools/exec.go of the component exec Tool. … Jul 14, 2026