Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42739
Total
3465
Critical
12744
High
12574
Medium
CVE ID Severity Score Description Published
CVE-2026-38343 UNKNOWN An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file. Aug 28, 2026
CVE-2026-18965 HIGH 8.8 PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with … Aug 28, 2026
CVE-2026-18717 HIGH 7.4 ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which may allow an attacker to impersonate the trusted peer, complete the TLS … Aug 28, 2026
CVE-2026-17610 UNKNOWN In SiSDK v2026.6.0 and earlier, high network traffic loads can cause a dropped ACK leading to a denial of service. This is only present for … Aug 28, 2026
CVE-2025-30156 HIGH 8.9 Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol encrypts … Aug 28, 2026
CVE-2026-81934 CRITICAL 9.8 Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated … Aug 27, 2026
CVE-2026-81931 UNKNOWN Unrestricted Upload of File with Dangerous Type in the product photo upload in Roskus Prospero Flow CRM before 5.16.0 allows an authenticated user holding the … Aug 27, 2026
CVE-2026-81893 MEDIUM 4.7 A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can … Aug 27, 2026
CVE-2026-81838 HIGH 7.1 A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to … Aug 27, 2026
CVE-2026-81834 MEDIUM 6.3 A weakness has been identified in RooCodeInc Roo-Code up to 3.51.1. Affected by this issue is the function ExecaTerminalProcess of the component README File Handler. … Aug 27, 2026
CVE-2026-81833 MEDIUM 5.5 A security flaw has been discovered in RooCodeInc Roo-Code up to 3.51.1. Affected by this vulnerability is the function optimizeQuery of the file src/utils/helpers.ts of … Aug 27, 2026
CVE-2026-81731 MEDIUM 5.4 Frappe 15.11.0 through 16.32.0 stores and renders the workspace card description without XSS filtering. The description field of the Workspace Link doctype is declared with … Aug 27, 2026
CVE-2026-81730 HIGH 8.2 Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The … Aug 27, 2026
CVE-2026-81729 MEDIUM 6.5 Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission. Documents::delete() in htdocs/api/class/api_documents.class.php calls dol_check_secure_access_document() with the mode argument 'read' when handling DELETE … Aug 27, 2026
CVE-2026-81728 HIGH 8.1 Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, … Aug 27, 2026
CVE-2026-81530 MEDIUM 5.6 A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management credential material supplied by the application to be reproduced … Aug 27, 2026
CVE-2026-81529 HIGH 7.1 Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C# Driver. When an application passes untrusted text into the driver's connection-URL … Aug 27, 2026
CVE-2026-81528 MEDIUM 5.4 A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write paths apply, so a value supplied as a replacement is … Aug 27, 2026
CVE-2026-81527 MEDIUM 6.5 A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver, in both aggregation expression and query filter translation. When … Aug 27, 2026
CVE-2026-81526 MEDIUM 6.5 The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding it in the request it sends to the server. … Aug 27, 2026
CVE-2026-81525 HIGH 8.1 The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for … Aug 27, 2026
CVE-2026-81524 MEDIUM 5.4 A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes … Aug 27, 2026
CVE-2026-81523 MEDIUM 4.4 A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied database identifier to be accepted without sanitization. The resulting impact is limited … Aug 27, 2026
CVE-2026-81522 HIGH 8.1 A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace … Aug 27, 2026
CVE-2026-81521 MEDIUM 6.5 The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name … Aug 27, 2026