Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42775
Total
3467
Critical
12772
High
12580
Medium
CVE ID Severity Score Description Published
CVE-2026-78002 HIGH 7.5 A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted … Aug 27, 2026
CVE-2026-75871 HIGH 8.2 GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, … Aug 27, 2026
CVE-2026-75573 MEDIUM 4.4 In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI … Aug 27, 2026
CVE-2026-75357 UNKNOWN An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili-bridge.js components. Aug 27, 2026
CVE-2026-75159 MEDIUM 5.9 An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication … Aug 27, 2026
CVE-2026-71402 MEDIUM 5.4 An out-of-bounds read was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capture.c reports the IP total length as the payload length … Aug 27, 2026
CVE-2026-71401 UNKNOWN An integer underflow was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capture.c does not verify that the IP total length field … Aug 27, 2026
CVE-2026-64896 UNKNOWN Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects T2000: … Aug 27, 2026
CVE-2026-5738 MEDIUM 6.1 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in BilPark Informatics Technologies Industry and Trade Inc. DoXBASE allows Cross Zone Scripting. This … Aug 27, 2026
CVE-2026-5680 HIGH 7.5 A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead … Aug 27, 2026
CVE-2026-59280 MEDIUM 4.3 Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input … Aug 27, 2026
CVE-2026-59272 MEDIUM 6.8 Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log … Aug 27, 2026
CVE-2026-57499 CRITICAL 9.1 Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows an … Aug 27, 2026
CVE-2026-56652 UNKNOWN Dool in versions up to 1.3.8 is vulnerable to a CSV injection vulnerability when exporting data to a CSV file, as it fails to sanitize … Aug 27, 2026
CVE-2026-56651 UNKNOWN Dool in versions up to 1.3.8 is vulnerable to symlink following when the "--devel" flag is used, as the application opens a log file without … Aug 27, 2026
CVE-2026-40526 MEDIUM 6.5 Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying absolute filesystem paths to the GET … Aug 27, 2026
CVE-2026-34674 HIGH 7.8 Substance3D - Sampler versions 5.1.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context … Aug 27, 2026
CVE-2026-30073 UNKNOWN An issue in the NssaiAvailabilitySubscriptionCreate component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request. Aug 27, 2026
CVE-2026-30072 UNKNOWN A NULL pointer dereference in the CDR processing path of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload. Aug 27, 2026
CVE-2026-30071 UNKNOWN An issue in the RechargePut function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. Aug 27, 2026
CVE-2026-30070 UNKNOWN An issue in the HandleGetSharedData function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. Aug 27, 2026
CVE-2026-30069 UNKNOWN A NULL pointer dereference in the UDMC registration handler component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted … Aug 27, 2026
CVE-2026-30068 UNKNOWN Improper input validation in the HandleUpdate function (/sbi/parameter_provision.go) of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. Aug 27, 2026
CVE-2026-30067 UNKNOWN An issue in the complexQueryFilterSubprocess function in the NRF Discovery service of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a … Aug 27, 2026
CVE-2026-30064 UNKNOWN Improper input validation in the buildFilter function (processor/processor.go) of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. Aug 27, 2026