Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42900
Total
3476
Critical
12865
High
12603
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-51106 | UNKNOWN | — | An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component | Aug 26, 2026 |
| CVE-2026-48786 | MEDIUM | 6.5 | Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll … | Aug 26, 2026 |
| CVE-2026-41262 | MEDIUM | 4.3 | Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET /api/latest/fleet/policies/{policy_id}) fails to verify … | Aug 26, 2026 |
| CVE-2026-36851 | UNKNOWN | — | Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration. | Aug 26, 2026 |
| CVE-2026-19485 | UNKNOWN | — | A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform … | Aug 26, 2026 |
| CVE-2025-61165 | UNKNOWN | — | An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file. | Aug 26, 2026 |
| CVE-2025-61164 | UNKNOWN | — | Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint. | Aug 26, 2026 |
| CVE-2025-61163 | UNKNOWN | — | Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin … | Aug 26, 2026 |
| CVE-2025-61162 | UNKNOWN | — | Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted request to the /api/internal/v1/users/{{USER_ID}} endpoint | Aug 26, 2026 |
| CVE-2026-76784 | UNKNOWN | — | Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge … | Aug 26, 2026 |
| CVE-2026-58474 | HIGH | 8.8 | whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to … | Aug 26, 2026 |
| CVE-2026-54256 | MEDIUM | 5.4 | Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend FileUpload form widget … | Aug 26, 2026 |
| CVE-2026-47841 | HIGH | 7.4 | An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store. Spring Security 7.1.0 Spring … | Aug 26, 2026 |
| CVE-2026-47837 | MEDIUM | 6.8 | Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This … | Aug 26, 2026 |
| CVE-2026-47836 | HIGH | 7.2 | The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config … | Aug 26, 2026 |
| CVE-2026-32639 | MEDIUM | 6.8 | Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor … | Aug 26, 2026 |
| CVE-2026-32593 | MEDIUM | 5.9 | Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is … | Aug 26, 2026 |
| CVE-2025-56798 | UNKNOWN | — | Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication … | Aug 26, 2026 |
| CVE-2025-29419 | UNKNOWN | — | CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack. | Aug 26, 2026 |
| CVE-2023-42179 | UNKNOWN | — | Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process. | Aug 26, 2026 |
| CVE-2026-80153 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 26, 2026 |
| CVE-2026-35445 | UNKNOWN | — | Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler … | Aug 26, 2026 |
| CVE-2026-32258 | HIGH | 8.1 | Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor … | Aug 26, 2026 |
| CVE-2026-32257 | HIGH | 8.1 | Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings … | Aug 26, 2026 |
| CVE-2020-15878 | UNKNOWN | — | An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a … | Aug 26, 2026 |