Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42900
Total
3476
Critical
12865
High
12603
Medium
CVE ID Severity Score Description Published
CVE-2026-56547 LOW 3.5 The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler requires the Logon Name and Mail Address … Aug 26, 2026
CVE-2026-54245 UNKNOWN Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional access integration in Fleet Premium is vulnerable … Aug 26, 2026
CVE-2026-49809 MEDIUM 6.5 Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low … Aug 26, 2026
CVE-2026-47848 MEDIUM 6.1 In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client may leak credentials. In order for this to happen, … Aug 26, 2026
CVE-2026-47844 MEDIUM 5.3 In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for this to happen, the server must be … Aug 26, 2026
CVE-2026-47843 LOW 3.7 In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrectly reuse a previously configured DNS resolver. Reactor Netty 1.3.0 - … Aug 26, 2026
CVE-2026-47842 MEDIUM 6.5 Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as the encryption mode encrypt data with AES/CBC using … Aug 26, 2026
CVE-2026-47834 MEDIUM 4.8 Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from untrusted sources. Spring Data JPA 4.1.0 Spring Data JPA … Aug 26, 2026
CVE-2026-46371 MEDIUM 6.5 Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) … Aug 26, 2026
CVE-2026-46370 MEDIUM 6.5 Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an … Aug 26, 2026
CVE-2026-46369 HIGH 7.5 Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound … Aug 26, 2026
CVE-2026-26449 UNKNOWN In Stomper 5e2741e when a client sends a SEND frame missing the destination header field, the server triggers a null pointer dereference (or access to … Aug 26, 2026
CVE-2026-26448 UNKNOWN Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection, and subsequently another client (or a later … Aug 26, 2026
CVE-2026-26447 UNKNOWN Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeatedly issues SUBSCRIBE commands for the same destination over one connection and then closes that … Aug 26, 2026
CVE-2026-26446 UNKNOWN Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peer, … Aug 26, 2026
CVE-2026-26445 UNKNOWN stomper 5e2741e is vulnerable to Denial of Service. A malicious client can send partial STOMP frames and keep the TCP connections open, which, combined with … Aug 26, 2026
CVE-2025-70340 UNKNOWN A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionality. An authenticated customer user can manipulate … Aug 26, 2026
CVE-2025-70293 UNKNOWN An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation … Aug 26, 2026
CVE-2025-70290 UNKNOWN An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. … Aug 26, 2026
CVE-2026-79940 MEDIUM 5.9 Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Control vulnerability. An unauthenticated attacker with remote access … Aug 26, 2026
CVE-2026-75466 UNKNOWN libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexed-color PNG image with a non-gray palette through tj3LoadImage12() or … Aug 26, 2026
CVE-2026-75325 UNKNOWN DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters. Aug 26, 2026
CVE-2026-71171 HIGH 7.2 Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in … Aug 26, 2026
CVE-2026-70419 CRITICAL 9.1 Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A … Aug 26, 2026
CVE-2026-63179 MEDIUM 4.9 Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, authenticated backend users can disclose … Aug 26, 2026