Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42900
Total
3476
Critical
12865
High
12603
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-56547 | LOW | 3.5 | The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler requires the Logon Name and Mail Address … | Aug 26, 2026 |
| CVE-2026-54245 | UNKNOWN | — | Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional access integration in Fleet Premium is vulnerable … | Aug 26, 2026 |
| CVE-2026-49809 | MEDIUM | 6.5 | Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low … | Aug 26, 2026 |
| CVE-2026-47848 | MEDIUM | 6.1 | In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client may leak credentials. In order for this to happen, … | Aug 26, 2026 |
| CVE-2026-47844 | MEDIUM | 5.3 | In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for this to happen, the server must be … | Aug 26, 2026 |
| CVE-2026-47843 | LOW | 3.7 | In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrectly reuse a previously configured DNS resolver. Reactor Netty 1.3.0 - … | Aug 26, 2026 |
| CVE-2026-47842 | MEDIUM | 6.5 | Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as the encryption mode encrypt data with AES/CBC using … | Aug 26, 2026 |
| CVE-2026-47834 | MEDIUM | 4.8 | Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from untrusted sources. Spring Data JPA 4.1.0 Spring Data JPA … | Aug 26, 2026 |
| CVE-2026-46371 | MEDIUM | 6.5 | Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) … | Aug 26, 2026 |
| CVE-2026-46370 | MEDIUM | 6.5 | Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an … | Aug 26, 2026 |
| CVE-2026-46369 | HIGH | 7.5 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound … | Aug 26, 2026 |
| CVE-2026-26449 | UNKNOWN | — | In Stomper 5e2741e when a client sends a SEND frame missing the destination header field, the server triggers a null pointer dereference (or access to … | Aug 26, 2026 |
| CVE-2026-26448 | UNKNOWN | — | Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection, and subsequently another client (or a later … | Aug 26, 2026 |
| CVE-2026-26447 | UNKNOWN | — | Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeatedly issues SUBSCRIBE commands for the same destination over one connection and then closes that … | Aug 26, 2026 |
| CVE-2026-26446 | UNKNOWN | — | Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peer, … | Aug 26, 2026 |
| CVE-2026-26445 | UNKNOWN | — | stomper 5e2741e is vulnerable to Denial of Service. A malicious client can send partial STOMP frames and keep the TCP connections open, which, combined with … | Aug 26, 2026 |
| CVE-2025-70340 | UNKNOWN | — | A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionality. An authenticated customer user can manipulate … | Aug 26, 2026 |
| CVE-2025-70293 | UNKNOWN | — | An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation … | Aug 26, 2026 |
| CVE-2025-70290 | UNKNOWN | — | An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. … | Aug 26, 2026 |
| CVE-2026-79940 | MEDIUM | 5.9 | Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Control vulnerability. An unauthenticated attacker with remote access … | Aug 26, 2026 |
| CVE-2026-75466 | UNKNOWN | — | libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexed-color PNG image with a non-gray palette through tj3LoadImage12() or … | Aug 26, 2026 |
| CVE-2026-75325 | UNKNOWN | — | DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters. | Aug 26, 2026 |
| CVE-2026-71171 | HIGH | 7.2 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in … | Aug 26, 2026 |
| CVE-2026-70419 | CRITICAL | 9.1 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A … | Aug 26, 2026 |
| CVE-2026-63179 | MEDIUM | 4.9 | Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, authenticated backend users can disclose … | Aug 26, 2026 |