Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43590
Total
3522
Critical
13030
High
12889
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-77508 | LOW | 3.5 | Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to … | Aug 26, 2026 |
| CVE-2026-75601 | MEDIUM | 4.3 | Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instances with both basic-auth and metrics features … | Aug 26, 2026 |
| CVE-2026-75334 | UNKNOWN | — | The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql parameter is stored in the t_report_sql_resource table through … | Aug 26, 2026 |
| CVE-2026-75327 | UNKNOWN | — | In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability: | Aug 26, 2026 |
| CVE-2026-74774 | MEDIUM | 5.9 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading … | Aug 26, 2026 |
| CVE-2026-74771 | MEDIUM | 6.5 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit … | Aug 26, 2026 |
| CVE-2026-74770 | HIGH | 8.8 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low … | Aug 26, 2026 |
| CVE-2026-71172 | MEDIUM | 4.3 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit … | Aug 26, 2026 |
| CVE-2026-71054 | MEDIUM | 6.5 | Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily exploitable vulnerability allows unauthenticated attacker with network … | Aug 26, 2026 |
| CVE-2026-68863 | HIGH | 7.5 | Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading … | Aug 26, 2026 |
| CVE-2026-68861 | HIGH | 8.8 | Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low … | Aug 26, 2026 |
| CVE-2026-68000 | UNKNOWN | — | The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directly concatenated into the LIMIT clause of SQL through … | Aug 26, 2026 |
| CVE-2026-67275 | MEDIUM | 5.3 | Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerability. An unauthenticated attacker with remote access could potentially exploit this … | Aug 26, 2026 |
| CVE-2026-66003 | UNKNOWN | — | Frappe is a full-stack web application framework written in Python and JavaScript. Prior to version 15.115.0, an access control bypass in the REST API allows … | Aug 26, 2026 |
| CVE-2026-60004 | CRITICAL | 9.8 | Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. | Aug 26, 2026 |
| CVE-2026-56547 | LOW | 3.5 | The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler requires the Logon Name and Mail Address … | Aug 26, 2026 |
| CVE-2026-54245 | UNKNOWN | — | Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional access integration in Fleet Premium is vulnerable … | Aug 26, 2026 |
| CVE-2026-49809 | MEDIUM | 6.5 | Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low … | Aug 26, 2026 |
| CVE-2026-47848 | MEDIUM | 6.1 | In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client may leak credentials. In order for this to happen, … | Aug 26, 2026 |
| CVE-2026-47844 | MEDIUM | 5.3 | In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for this to happen, the server must be … | Aug 26, 2026 |
| CVE-2026-47843 | LOW | 3.7 | In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrectly reuse a previously configured DNS resolver. Reactor Netty 1.3.0 - … | Aug 26, 2026 |
| CVE-2026-47842 | MEDIUM | 6.5 | Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as the encryption mode encrypt data with AES/CBC using … | Aug 26, 2026 |
| CVE-2026-47834 | MEDIUM | 4.8 | Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from untrusted sources. Spring Data JPA 4.1.0 Spring Data JPA … | Aug 26, 2026 |
| CVE-2026-46371 | MEDIUM | 6.5 | Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) … | Aug 26, 2026 |
| CVE-2026-46370 | MEDIUM | 6.5 | Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an … | Aug 26, 2026 |