Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42775
Total
3467
Critical
12772
High
12580
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-78002 | HIGH | 7.5 | A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted … | Aug 27, 2026 |
| CVE-2026-75871 | HIGH | 8.2 | GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, … | Aug 27, 2026 |
| CVE-2026-75573 | MEDIUM | 4.4 | In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI … | Aug 27, 2026 |
| CVE-2026-75357 | UNKNOWN | — | An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili-bridge.js components. | Aug 27, 2026 |
| CVE-2026-75159 | MEDIUM | 5.9 | An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication … | Aug 27, 2026 |
| CVE-2026-71402 | MEDIUM | 5.4 | An out-of-bounds read was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capture.c reports the IP total length as the payload length … | Aug 27, 2026 |
| CVE-2026-71401 | UNKNOWN | — | An integer underflow was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capture.c does not verify that the IP total length field … | Aug 27, 2026 |
| CVE-2026-64896 | UNKNOWN | — | Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects T2000: … | Aug 27, 2026 |
| CVE-2026-5738 | MEDIUM | 6.1 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in BilPark Informatics Technologies Industry and Trade Inc. DoXBASE allows Cross Zone Scripting. This … | Aug 27, 2026 |
| CVE-2026-5680 | HIGH | 7.5 | A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead … | Aug 27, 2026 |
| CVE-2026-59280 | MEDIUM | 4.3 | Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input … | Aug 27, 2026 |
| CVE-2026-59272 | MEDIUM | 6.8 | Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is exposed to man-in-the-middle interception of every log … | Aug 27, 2026 |
| CVE-2026-57499 | CRITICAL | 9.1 | Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows an … | Aug 27, 2026 |
| CVE-2026-56652 | UNKNOWN | — | Dool in versions up to 1.3.8 is vulnerable to a CSV injection vulnerability when exporting data to a CSV file, as it fails to sanitize … | Aug 27, 2026 |
| CVE-2026-56651 | UNKNOWN | — | Dool in versions up to 1.3.8 is vulnerable to symlink following when the "--devel" flag is used, as the application opens a log file without … | Aug 27, 2026 |
| CVE-2026-40526 | MEDIUM | 6.5 | Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying absolute filesystem paths to the GET … | Aug 27, 2026 |
| CVE-2026-34674 | HIGH | 7.8 | Substance3D - Sampler versions 5.1.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context … | Aug 27, 2026 |
| CVE-2026-30073 | UNKNOWN | — | An issue in the NssaiAvailabilitySubscriptionCreate component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | Aug 27, 2026 |
| CVE-2026-30072 | UNKNOWN | — | A NULL pointer dereference in the CDR processing path of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload. | Aug 27, 2026 |
| CVE-2026-30071 | UNKNOWN | — | An issue in the RechargePut function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | Aug 27, 2026 |
| CVE-2026-30070 | UNKNOWN | — | An issue in the HandleGetSharedData function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | Aug 27, 2026 |
| CVE-2026-30069 | UNKNOWN | — | A NULL pointer dereference in the UDMC registration handler component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted … | Aug 27, 2026 |
| CVE-2026-30068 | UNKNOWN | — | Improper input validation in the HandleUpdate function (/sbi/parameter_provision.go) of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | Aug 27, 2026 |
| CVE-2026-30067 | UNKNOWN | — | An issue in the complexQueryFilterSubprocess function in the NRF Discovery service of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a … | Aug 27, 2026 |
| CVE-2026-30064 | UNKNOWN | — | Improper input validation in the buildFilter function (processor/processor.go) of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | Aug 27, 2026 |