Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42400
Total
3455
Critical
12534
High
12466
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-55108 | HIGH | 8.5 | KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader … | Aug 28, 2026 |
| CVE-2026-55068 | UNKNOWN | — | free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handler at PUT /nnrf-nfm/v1/nf-instances/{nfInstanceID} accepts NF Profiles without … | Aug 28, 2026 |
| CVE-2026-55067 | MEDIUM | 5.0 | Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket} allows the request body project_view_id value to be mass assigned by Bucket.Update … | Aug 28, 2026 |
| CVE-2026-55066 | HIGH | 7.1 | Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}/tasks accepts a body supplied task_id but TaskBucket.CanUpdate in pkg/models/kanban_task_bucket.go authorizes only the … | Aug 28, 2026 |
| CVE-2026-55065 | HIGH | 8.1 | Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view identifier from another … | Aug 28, 2026 |
| CVE-2026-55064 | MEDIUM | 4.3 | Vikunja is an open-source self-hosted task management platform. From 2.3.0 until 2.4.0, a user with Write but not Admin permission on a shared child project … | Aug 28, 2026 |
| CVE-2026-54788 | HIGH | 7.5 | dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/tracecontext.rs parses the W3C tracestate header and collects every semicolon-separated key and value … | Aug 28, 2026 |
| CVE-2026-54766 | UNKNOWN | — | Vikunja is an open-source self-hosted task management platform. From 0.21.0 until 2.4.0, the project duplication operation in pkg/models/project_duplicate.go allows an authenticated user who can read … | Aug 28, 2026 |
| CVE-2026-54755 | CRITICAL | 9.6 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and … | Aug 28, 2026 |
| CVE-2026-54754 | CRITICAL | 9.6 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading asset.Royalties.MarketPercentage … | Aug 28, 2026 |
| CVE-2026-54746 | MEDIUM | 6.4 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. From 0.40.0 until 0.91.1, the Dispatcher gRPC service does not … | Aug 28, 2026 |
| CVE-2026-54745 | CRITICAL | 10.0 | Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request … | Aug 28, 2026 |
| CVE-2026-51660 | UNKNOWN | — | Incorrect access control in the getIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IP and port filtering rules via sending a crafted … | Aug 28, 2026 |
| CVE-2026-51659 | UNKNOWN | — | Incorrect access control in the getUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DMZ configuration information via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51658 | UNKNOWN | — | Incorrect access control in the getDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DMZ configuration information via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51657 | UNKNOWN | — | Incorrect access control in the getSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain syslog-related configuration via sending a crafted POST request to … | Aug 28, 2026 |
| CVE-2026-51656 | UNKNOWN | — | Incorrect access control in the getVpnPassCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain VPN pass-through and WAN ping filter settings via sending … | Aug 28, 2026 |
| CVE-2026-51655 | UNKNOWN | — | Incorrect access control in the getMacFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain MAC filter rules via sending a crafted POST request … | Aug 28, 2026 |
| CVE-2026-51654 | UNKNOWN | — | Incorrect access control in the getScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain schedule or scheduled-reboot configuration information via sending a crafted … | Aug 28, 2026 |
| CVE-2026-51653 | UNKNOWN | — | Incorrect access control in the getStorageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain storage feature state information via sending a crafted POST … | Aug 28, 2026 |
| CVE-2026-51652 | UNKNOWN | — | Incorrect access control in the getUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain UPnP enablement and parsed port-mapping information via sending a … | Aug 28, 2026 |
| CVE-2026-51651 | UNKNOWN | — | Incorrect access control in the getSmartQosCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Smart QoS configuration and rules via sending a crafted … | Aug 28, 2026 |
| CVE-2026-51650 | UNKNOWN | — | Incorrect access control in the getRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain remote-management enablement and port information via sending a crafted … | Aug 28, 2026 |
| CVE-2026-51649 | UNKNOWN | — | Incorrect access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain diagnostic configuration and ping log contents via sending a … | Aug 28, 2026 |
| CVE-2026-51648 | UNKNOWN | — | Incorrect access control in the getWanInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN information returned by the endpoint via sending a … | Aug 28, 2026 |