Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42739
Total
3465
Critical
12744
High
12574
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-38343 | UNKNOWN | — | An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file. | Aug 28, 2026 |
| CVE-2026-18965 | HIGH | 8.8 | PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with … | Aug 28, 2026 |
| CVE-2026-18717 | HIGH | 7.4 | ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which may allow an attacker to impersonate the trusted peer, complete the TLS … | Aug 28, 2026 |
| CVE-2026-17610 | UNKNOWN | — | In SiSDK v2026.6.0 and earlier, high network traffic loads can cause a dropped ACK leading to a denial of service. This is only present for … | Aug 28, 2026 |
| CVE-2025-30156 | HIGH | 8.9 | Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol encrypts … | Aug 28, 2026 |
| CVE-2026-81934 | CRITICAL | 9.8 | Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated … | Aug 27, 2026 |
| CVE-2026-81931 | UNKNOWN | — | Unrestricted Upload of File with Dangerous Type in the product photo upload in Roskus Prospero Flow CRM before 5.16.0 allows an authenticated user holding the … | Aug 27, 2026 |
| CVE-2026-81893 | MEDIUM | 4.7 | A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can … | Aug 27, 2026 |
| CVE-2026-81838 | HIGH | 7.1 | A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to … | Aug 27, 2026 |
| CVE-2026-81834 | MEDIUM | 6.3 | A weakness has been identified in RooCodeInc Roo-Code up to 3.51.1. Affected by this issue is the function ExecaTerminalProcess of the component README File Handler. … | Aug 27, 2026 |
| CVE-2026-81833 | MEDIUM | 5.5 | A security flaw has been discovered in RooCodeInc Roo-Code up to 3.51.1. Affected by this vulnerability is the function optimizeQuery of the file src/utils/helpers.ts of … | Aug 27, 2026 |
| CVE-2026-81731 | MEDIUM | 5.4 | Frappe 15.11.0 through 16.32.0 stores and renders the workspace card description without XSS filtering. The description field of the Workspace Link doctype is declared with … | Aug 27, 2026 |
| CVE-2026-81730 | HIGH | 8.2 | Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The … | Aug 27, 2026 |
| CVE-2026-81729 | MEDIUM | 6.5 | Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission. Documents::delete() in htdocs/api/class/api_documents.class.php calls dol_check_secure_access_document() with the mode argument 'read' when handling DELETE … | Aug 27, 2026 |
| CVE-2026-81728 | HIGH | 8.1 | Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, … | Aug 27, 2026 |
| CVE-2026-81530 | MEDIUM | 5.6 | A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management credential material supplied by the application to be reproduced … | Aug 27, 2026 |
| CVE-2026-81529 | HIGH | 7.1 | Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C# Driver. When an application passes untrusted text into the driver's connection-URL … | Aug 27, 2026 |
| CVE-2026-81528 | MEDIUM | 5.4 | A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write paths apply, so a value supplied as a replacement is … | Aug 27, 2026 |
| CVE-2026-81527 | MEDIUM | 6.5 | A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver, in both aggregation expression and query filter translation. When … | Aug 27, 2026 |
| CVE-2026-81526 | MEDIUM | 6.5 | The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding it in the request it sends to the server. … | Aug 27, 2026 |
| CVE-2026-81525 | HIGH | 8.1 | The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for … | Aug 27, 2026 |
| CVE-2026-81524 | MEDIUM | 5.4 | A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes … | Aug 27, 2026 |
| CVE-2026-81523 | MEDIUM | 4.4 | A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied database identifier to be accepted without sanitization. The resulting impact is limited … | Aug 27, 2026 |
| CVE-2026-81522 | HIGH | 8.1 | A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace … | Aug 27, 2026 |
| CVE-2026-81521 | MEDIUM | 6.5 | The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name … | Aug 27, 2026 |