Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

43670
Total
3528
Critical
13050
High
12909
Medium
CVE ID Severity Score Description Published
CVE-2026-47843 LOW 3.7 In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrectly reuse a previously configured DNS resolver. Reactor Netty 1.3.0 - … Aug 26, 2026
CVE-2026-47842 MEDIUM 6.5 Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as the encryption mode encrypt data with AES/CBC using … Aug 26, 2026
CVE-2026-47834 MEDIUM 4.8 Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from untrusted sources. Spring Data JPA 4.1.0 Spring Data JPA … Aug 26, 2026
CVE-2026-46371 MEDIUM 6.5 Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) … Aug 26, 2026
CVE-2026-46370 MEDIUM 6.5 Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an … Aug 26, 2026
CVE-2026-46369 HIGH 7.5 Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound … Aug 26, 2026
CVE-2026-26449 UNKNOWN In Stomper 5e2741e when a client sends a SEND frame missing the destination header field, the server triggers a null pointer dereference (or access to … Aug 26, 2026
CVE-2026-26448 UNKNOWN Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection, and subsequently another client (or a later … Aug 26, 2026
CVE-2026-26447 UNKNOWN Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeatedly issues SUBSCRIBE commands for the same destination over one connection and then closes that … Aug 26, 2026
CVE-2026-26446 UNKNOWN Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peer, … Aug 26, 2026
CVE-2026-26445 UNKNOWN stomper 5e2741e is vulnerable to Denial of Service. A malicious client can send partial STOMP frames and keep the TCP connections open, which, combined with … Aug 26, 2026
CVE-2025-70340 UNKNOWN A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionality. An authenticated customer user can manipulate … Aug 26, 2026
CVE-2025-70293 UNKNOWN An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation … Aug 26, 2026
CVE-2025-70290 UNKNOWN An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. … Aug 26, 2026
CVE-2026-79940 MEDIUM 5.9 Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Control vulnerability. An unauthenticated attacker with remote access … Aug 26, 2026
CVE-2026-75466 UNKNOWN libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexed-color PNG image with a non-gray palette through tj3LoadImage12() or … Aug 26, 2026
CVE-2026-75325 UNKNOWN DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters. Aug 26, 2026
CVE-2026-71171 HIGH 7.2 Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in … Aug 26, 2026
CVE-2026-70419 CRITICAL 9.1 Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A … Aug 26, 2026
CVE-2026-63179 MEDIUM 4.9 Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, authenticated backend users can disclose … Aug 26, 2026
CVE-2026-51106 UNKNOWN An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component Aug 26, 2026
CVE-2026-48786 MEDIUM 6.5 Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll … Aug 26, 2026
CVE-2026-41262 MEDIUM 4.3 Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET /api/latest/fleet/policies/{policy_id}) fails to verify … Aug 26, 2026
CVE-2026-36851 UNKNOWN Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration. Aug 26, 2026
CVE-2026-19485 UNKNOWN A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform … Aug 26, 2026