Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
33951
Total
2635
Critical
10034
High
10234
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-50655 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /thd_group.asp endpoint. | Apr 08, 2026 |
| CVE-2025-50654 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of the id parameter in the /thd_member.asp endpoint. | Apr 08, 2026 |
| CVE-2025-50653 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name and mem parameters in the /time_group.asp endpoint. | Apr 08, 2026 |
| CVE-2025-50652 | UNKNOWN | — | An issue in D-Link DI-8003 16.07.26A1 related to improper handling of the id parameter in the /saveparm_usb.asp endpoint. | Apr 08, 2026 |
| CVE-2025-50650 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate validation of input size in the routes_static parameter in the /router.asp endpoint. | Apr 08, 2026 |
| CVE-2025-50649 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper input validation in the vlan_name parameter in the /shut_set.asp endpoint. | Apr 08, 2026 |
| CVE-2025-50648 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate input validation in the /tggl.asp endpoint. | Apr 08, 2026 |
| CVE-2025-50647 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1, specifically in the handling of the wans parameter in the qos.asp endpoint. | Apr 08, 2026 |
| CVE-2025-50646 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to insufficient input validation on the name parameter in the /qos_type_asp.asp endpoint. | Apr 08, 2026 |
| CVE-2025-50645 | UNKNOWN | — | A vulnerability has been discovered in D-Link DI-8003 16.07.26A1, which can lead to a buffer overflow when the s parameter in the pppoe_list_opt.asp endpoint is … | Apr 08, 2026 |
| CVE-2025-50644 | UNKNOWN | — | A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of user input in the qj.asp endpoint. | Apr 08, 2026 |
| CVE-2025-30650 | MEDIUM | 6.7 | A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to line … | Apr 08, 2026 |
| CVE-2026-33756 | HIGH | 7.5 | Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query batching by submitting multiple GraphQL operations in a … | Apr 08, 2026 |
| CVE-2026-33466 | HIGH | 8.1 | Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code execution via Relative … | Apr 08, 2026 |
| CVE-2026-33459 | MEDIUM | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with access to the automatic import … | Apr 08, 2026 |
| CVE-2026-33458 | MEDIUM | 6.3 | Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user with workflow creation and execution privileges can bypass host … | Apr 08, 2026 |
| CVE-2026-32591 | MEDIUM | 5.2 | A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes … | Apr 08, 2026 |
| CVE-2026-32590 | HIGH | 7.1 | A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using … | Apr 08, 2026 |
| CVE-2026-32589 | HIGH | 7.1 | A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can … | Apr 08, 2026 |
| CVE-2025-52222 | UNKNOWN | — | D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-8400 v16.07.26A1, DI-8004w v16.07.26A1, DI-8100 v16.07.26A1, and DI-8100G v17.12.20A1 were discovered to contain a … | Apr 08, 2026 |
| CVE-2025-52221 | UNKNOWN | — | Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameters. | Apr 08, 2026 |
| CVE-2025-45059 | UNKNOWN | — | D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function. This vulnerability allows attackers to cause a … | Apr 08, 2026 |
| CVE-2025-45058 | UNKNOWN | — | D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the fx parameter in the jingx_asp function. This vulnerability allows attackers to cause a … | Apr 08, 2026 |
| CVE-2025-45057 | UNKNOWN | — | D-Link DI-8300 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp function. This vulnerability allows attackers to cause a … | Apr 08, 2026 |
| CVE-2026-4837 | MEDIUM | 6.6 | An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve remote code execution as … | Apr 08, 2026 |