Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

43590
Total
3522
Critical
13030
High
12889
Medium
CVE ID Severity Score Description Published
CVE-2026-47861 MEDIUM 6.3 An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an … Aug 27, 2026
CVE-2026-47860 MEDIUM 6.5 An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single … Aug 27, 2026
CVE-2026-47859 MEDIUM 5.4 RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the sender-supplied octet count of an … Aug 27, 2026
CVE-2026-47857 MEDIUM 5.9 In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - … Aug 27, 2026
CVE-2026-47856 MEDIUM 6.3 Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with … Aug 27, 2026
CVE-2026-47852 HIGH 7.5 A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI … Aug 27, 2026
CVE-2026-47851 HIGH 7.5 Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI … Aug 27, 2026
CVE-2026-47850 MEDIUM 4.3 Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP PUT against an immutable target type. … Aug 27, 2026
CVE-2026-47845 MEDIUM 5.3 In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order for this to happen, … Aug 27, 2026
CVE-2026-81203 HIGH 7.3 A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of … Aug 26, 2026
CVE-2026-80158 MEDIUM 5.5 A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when … Aug 26, 2026
CVE-2026-75340 CRITICAL 9.1 The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF). Aug 26, 2026
CVE-2026-75338 CRITICAL 9.8 disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/config/list and /api/config/simple/list are exposed without authentication. The … Aug 26, 2026
CVE-2026-75336 CRITICAL 9.8 Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json. Aug 26, 2026
CVE-2026-75332 CRITICAL 9.1 Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download(). Aug 26, 2026
CVE-2026-75330 CRITICAL 9.8 The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through … Aug 26, 2026
CVE-2026-69129 UNKNOWN KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 2.0.0, cluster-scoped APIs do not consistently validate per-cluster access, allowing an authenticated … Aug 26, 2026
CVE-2026-65956 UNKNOWN KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public … Aug 26, 2026
CVE-2026-47666 HIGH 7.6 Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font … Aug 26, 2026
CVE-2026-47665 HIGH 8.7 Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, … Aug 26, 2026
CVE-2026-21808 MEDIUM 4.1 HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker … Aug 26, 2026
CVE-2026-21807 LOW 3.9 HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow. Aug 26, 2026
CVE-2026-18823 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 26, 2026
CVE-2025-62341 LOW 3.7 HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in certain … Aug 26, 2026
CVE-2026-81202 HIGH 7.3 A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD … Aug 26, 2026