Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
53238
Total
4231
Critical
15843
High
15500
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-57027 | MEDIUM | 6.5 | A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series devices … | Jul 09, 2026 |
| CVE-2026-57026 | HIGH | 7.5 | An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX … | Jul 09, 2026 |
| CVE-2026-57025 | MEDIUM | 5.5 | A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a … | Jul 09, 2026 |
| CVE-2026-57024 | MEDIUM | 5.3 | A Use of Multiple Resources with Duplicate Identifier vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX with SPC3 and SRX … | Jul 09, 2026 |
| CVE-2026-57023 | HIGH | 7.5 | An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and … | Jul 09, 2026 |
| CVE-2026-57022 | MEDIUM | 5.9 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX with SPC3 and … | Jul 09, 2026 |
| CVE-2026-57021 | MEDIUM | 5.3 | An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service … | Jul 09, 2026 |
| CVE-2026-57020 | MEDIUM | 6.5 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on QFX10000 Series allows an … | Jul 09, 2026 |
| CVE-2026-57019 | MEDIUM | 6.5 | An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an … | Jul 09, 2026 |
| CVE-2026-55689 | MEDIUM | 6.8 | OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, OpenFGA's OIDC authenticator skipped JWT audience validation when authn.method was set to oidc, authn.oidc.issuer … | Jul 09, 2026 |
| CVE-2026-55605 | MEDIUM | 5.3 | DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.8.0, the self-hosted HTTP transport of `@arikusi/deepseek-mcp-server` … | Jul 09, 2026 |
| CVE-2026-55604 | HIGH | 8.6 | DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.7.0, the process-global `SessionStore` accepts caller-supplied `session_id` … | Jul 09, 2026 |
| CVE-2026-55424 | UNKNOWN | — | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a topic "featured link" was not sufficiently normalized and escaped before being … | Jul 09, 2026 |
| CVE-2026-55170 | UNKNOWN | — | OpenFGA is an authorization/permission engine built for developers. Prior to 1.18.0, when MySQL is being used as the datastore and authorization decisions rely on case-sensitive … | Jul 09, 2026 |
| CVE-2026-53963 | HIGH | 7.3 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escaped … | Jul 09, 2026 |
| CVE-2026-53962 | MEDIUM | 5.4 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, insufficient SVG sanitization in upload and user avatar handling could lead to … | Jul 09, 2026 |
| CVE-2026-53961 | MEDIUM | 6.5 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the AWS SES bounce webhook at POST /webhooks/aws verified that SNS messages … | Jul 09, 2026 |
| CVE-2026-49256 | UNKNOWN | — | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, restricted tag and tag-group names attached to publicly readable categories as allowed_tags, … | Jul 09, 2026 |
| CVE-2026-46413 | MEDIUM | 6.5 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, regular users could route direct S3 multipart uploads through ExternalUploadManager into the … | Jul 09, 2026 |
| CVE-2026-45788 | UNKNOWN | — | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, secure uploads could be exposed by pull_hotlinked_images when an attacker knew the … | Jul 09, 2026 |
| CVE-2026-45780 | MEDIUM | 5.3 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, EventSerializer could expose invited group names, sample invitees, and attendance statistics to … | Jul 09, 2026 |
| CVE-2026-44787 | HIGH | 8.2 | Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the signup flow could allow newly registered users to set primary_group_id and … | Jul 09, 2026 |
| CVE-2026-39246 | UNKNOWN | — | decompress before 4.2.2 allows arbitrary symlink creation during archive extraction. When processing symlink entries (type === 'symlink'), the x.linkname field from the archive is passed … | Jul 09, 2026 |
| CVE-2026-39245 | MEDIUM | 6.2 | decompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file write. The safeMakeDir function (index.js line 29) and the … | Jul 09, 2026 |
| CVE-2026-39243 | MEDIUM | 5.5 | decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. When processing hardlink entries (type === 'link'), the … | Jul 09, 2026 |