Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52841
Total
4211
Critical
15646
High
15361
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-15482 | HIGH | 7.3 | A weakness has been identified in Aster Telecom Azcall 10/11. This issue affects some unknown processing of the file /azcall/adm/gestao_loja/sis.php?t=consultar of the component HTTP Handler. … | Jul 12, 2026 |
| CVE-2026-15481 | HIGH | 8.8 | A security flaw has been discovered in Trendnet TEW-635BRM up to 1.00.03. This vulnerability affects the function ipoa_test of the file /sbin/rc of the component … | Jul 12, 2026 |
| CVE-2026-15480 | HIGH | 8.8 | A vulnerability was identified in Trendnet TEW-635BRM up to 1.00.03. This affects the function start_httpd of the file /sbin/rc of the component Web Service. Such … | Jul 12, 2026 |
| CVE-2026-15479 | HIGH | 7.3 | A vulnerability was found in H3C NX15 V100R017. Affected by this vulnerability is the function change_passwd of the file /api/login/modify of the component Administrator Password … | Jul 12, 2026 |
| CVE-2026-15478 | MEDIUM | 6.3 | A flaw has been found in IceHRM up to 35.0.1. This impacts an unknown function of the file core/src/Reports/User/Reports/EmployeeAttendanceReport.php of the component UserReport Endpoint. Executing … | Jul 12, 2026 |
| CVE-2026-15477 | MEDIUM | 6.3 | A vulnerability was detected in Bahmni bahmnicore up to 0.93. This affects the function additionalParams of the file /openmrs/ws/rest/v1/bahmnicore/sql of the component Search Endpoint. Performing … | Jul 12, 2026 |
| CVE-2026-15476 | MEDIUM | 5.3 | A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in the library diskbckp.sys of the component … | Jul 12, 2026 |
| CVE-2026-15475 | MEDIUM | 5.3 | A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the … | Jul 12, 2026 |
| CVE-2026-15474 | MEDIUM | 4.3 | A security flaw has been discovered in Eleveo Call Recording Software 9.7.0. Impacted is an unknown function of the file /callrec/audio.jsp of the component Call … | Jul 12, 2026 |
| CVE-2026-15473 | MEDIUM | 6.3 | A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This issue affects some unknown processing of the file /callrec/restoreCallAction.do of the component Recorded Calls … | Jul 12, 2026 |
| CVE-2026-15472 | MEDIUM | 4.3 | A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/composeEmailAction.do. Executing a manipulation can lead to … | Jul 12, 2026 |
| CVE-2026-15471 | MEDIUM | 4.3 | A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/pci_dss_status.jsp. Performing a manipulation results in improper … | Jul 12, 2026 |
| CVE-2026-15470 | MEDIUM | 4.3 | A vulnerability has been found in Eleveo Call Recording Software 9.7.0. Affected by this issue is some unknown functionality of the file /callrec/group.jsp. Such manipulation … | Jul 12, 2026 |
| CVE-2026-58281 | HIGH | 8.3 | Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | Jul 11, 2026 |
| CVE-2026-10660 | MEDIUM | 6.4 | The Bluetooth BAP Broadcast Assistant GATT client in subsys/bluetooth/audio/bap_broadcast_assistant.c reassembled remote Broadcast Receive State data into a single file-static net_buf_simple (att_buf, BT_ATT_MAX_ATTRIBUTE_LEN = 512 bytes) … | Jul 11, 2026 |
| CVE-2026-61870 | LOW | 2.9 | ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing specially crafted … | Jul 11, 2026 |
| CVE-2026-61861 | LOW | 3.7 | ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory allocation fails. Attackers can trigger memory allocation failures to cause a dangling … | Jul 11, 2026 |
| CVE-2026-61858 | LOW | 3.3 | ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to … | Jul 11, 2026 |
| CVE-2026-61857 | LOW | 3.7 | ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially … | Jul 11, 2026 |
| CVE-2026-61465 | LOW | 3.3 | ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply … | Jul 11, 2026 |
| CVE-2026-61454 | MEDIUM | 5.3 | The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and its subroutes). This … | Jul 11, 2026 |
| CVE-2026-61448 | UNKNOWN | — | Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8.6.83. When an uploaded file's extension … | Jul 11, 2026 |
| CVE-2026-61447 | CRITICAL | 10.0 | PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers … | Jul 11, 2026 |
| CVE-2026-61445 | CRITICAL | 9.9 | PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM … | Jul 11, 2026 |
| CVE-2026-61442 | HIGH | 7.1 | PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for projects, issues, and agents, which only require workspace-member role. A … | Jul 11, 2026 |