Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
53238
Total
4231
Critical
15843
High
15500
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-38076 | UNKNOWN | — | An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input. | Jul 09, 2026 |
| CVE-2026-33803 | MEDIUM | 6.5 | An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited … | Jul 09, 2026 |
| CVE-2026-33802 | MEDIUM | 5.5 | A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS). … | Jul 09, 2026 |
| CVE-2026-15276 | LOW | 3.3 | A flaw has been found in pdeljanov Symphonia up to 0.6.0. This vulnerability affects unknown code of the component Metadata Handler. This manipulation causes denial … | Jul 09, 2026 |
| CVE-2026-15274 | LOW | 3.3 | A vulnerability was detected in lo48576 fbxcel up to 0.9.0. This affects an unknown part of the file src/pull_parser/v7400/parser.rs of the component Node Header Handler. … | Jul 09, 2026 |
| CVE-2026-15271 | HIGH | 7.5 | A security vulnerability has been detected in TOTOLINK A3000RU, A3100R, A950RG, AC1200T10, CP450, CS185R_T10 and EX200 up to 20260906. Affected by this issue is some … | Jul 09, 2026 |
| CVE-2026-60120 | MEDIUM | 5.4 | Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to execute arbitrary JavaScript in administrator browsers by … | Jul 09, 2026 |
| CVE-2026-55865 | UNKNOWN | — | Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.1, given a malformed {% case %} tag without an associated {% … | Jul 09, 2026 |
| CVE-2026-55212 | HIGH | 7.1 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, the Studio API class definition creation endpoint POST /pimcore-studio/api/class/definition/configuration-view/detail/create is … | Jul 09, 2026 |
| CVE-2026-55208 | HIGH | 7.7 | Pimcore Studio Backend Bundle is the backend bundle for Pimcore Studio. Prior to 2025.4.6 and 2026.1.6, an authenticated user can extract the admin password hash … | Jul 09, 2026 |
| CVE-2026-55207 | HIGH | 8.8 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated attacker who knows a valid admin username can … | Jul 09, 2026 |
| CVE-2026-51926 | UNKNOWN | — | An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerability was identified in … | Jul 09, 2026 |
| CVE-2026-51925 | HIGH | 8.1 | A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to execute arbitrary code via the dfm-menu_report.php component. … | Jul 09, 2026 |
| CVE-2026-51924 | HIGH | 8.1 | An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and report.php component | Jul 09, 2026 |
| CVE-2026-51923 | HIGH | 8.1 | An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code via the user settings … | Jul 09, 2026 |
| CVE-2026-33801 | MEDIUM | 6.5 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows … | Jul 09, 2026 |
| CVE-2026-33800 | MEDIUM | 6.5 | An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent … | Jul 09, 2026 |
| CVE-2026-33799 | MEDIUM | 4.3 | An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific … | Jul 09, 2026 |
| CVE-2026-33794 | MEDIUM | 5.9 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand) of Juniper Networks Junos OS Evolved on PTX Series allows … | Jul 09, 2026 |
| CVE-2026-31267 | MEDIUM | 5.7 | Mercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 is vulnerable to Buffer Overflow in the administrative web interface. A stack buffer overflow vulnerability in the administrative web interface … | Jul 09, 2026 |
| CVE-2026-21901 | MEDIUM | 4.4 | A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting … | Jul 09, 2026 |
| CVE-2025-45422 | UNKNOWN | — | Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and make arbitrary changes to port forwarding rules. | Jul 09, 2026 |
| CVE-2026-15270 | HIGH | 7.5 | A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/boa.conf of the component Web … | Jul 09, 2026 |
| CVE-2026-0278 | UNKNOWN | — | Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement … | Jul 09, 2026 |
| CVE-2026-0277 | UNKNOWN | — | An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. … | Jul 09, 2026 |