Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43670
Total
3528
Critical
13050
High
12909
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-81033 | MEDIUM | 5.3 | Automatisch reveals whether an address is registered through the response to its forgot-password request. The controller at packages/backend/src/controllers/internal/api/v1/users/forgot-password.js looks the address up and chains a … | Aug 26, 2026 |
| CVE-2026-81032 | CRITICAL | 9.8 | NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all … | Aug 26, 2026 |
| CVE-2026-81031 | HIGH | 7.2 | IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the request. The update handler in backend/src/controllers/middlewaresControllers/createUserController/updatePassword.js resolves … | Aug 26, 2026 |
| CVE-2026-81030 | MEDIUM | 6.5 | Mage AI does not confine the paths accepted by its browser-items API to the project directory. BrowserItemResource in mage_ai/api/resources/BrowserItemResource.py passes a caller-supplied path to the … | Aug 26, 2026 |
| CVE-2026-81029 | HIGH | 8.1 | OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the … | Aug 26, 2026 |
| CVE-2026-81028 | MEDIUM | 4.9 | ZLMediaKit confines the downloadFile API to a configured set of root directories with a prefix comparison that does not account for directory boundaries. The configuration … | Aug 26, 2026 |
| CVE-2026-81027 | HIGH | 8.5 | one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a specific channel either through a suffix … | Aug 26, 2026 |
| CVE-2026-80428 | CRITICAL | 9.8 | ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIAS/AuthShibboleth/resources/shib_logout.php runs in a context that ilInitialisation exempts from authentication, and … | Aug 26, 2026 |
| CVE-2026-80427 | HIGH | 8.4 | bestzip builds the argument list for the system zip utility without separating options from operands. The destination archive path and the caller-supplied source paths are … | Aug 26, 2026 |
| CVE-2026-80426 | HIGH | 7.1 | FiftyOne renders a dataset field's description as markup. The sidebar field-information component at app/packages/core/src/components/FieldLabelAndInfo/index.tsx passes the description string to React's dangerouslySetInnerHTML, and no layer between … | Aug 26, 2026 |
| CVE-2026-54614 | MEDIUM | 4.3 | DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feature in src/Controller/MailPreviewController.php accepts a route-controlled previewName value in … | Aug 26, 2026 |
| CVE-2026-54606 | UNKNOWN | — | SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 3.1.4, the SunEditor Embed plugin in src/plugins/modal/embed.js parses attacker-controlled … | Aug 26, 2026 |
| CVE-2026-54569 | CRITICAL | 9.8 | SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution … | Aug 26, 2026 |
| CVE-2026-48549 | MEDIUM | 6.5 | Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi. When no Cookie header is present, the double-submit cookie protection … | Aug 26, 2026 |
| CVE-2026-48548 | MEDIUM | 6.5 | Nagios Core before 4.5.12 contains a cross-site request forgery vulnerability in cmd.cgi where the CSRF protection mechanism passes validation when the NagFormId cookie is absent. … | Aug 26, 2026 |
| CVE-2026-80589 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: block: stop the timeout timer when releasing a never added disk disk_release() undoes blk_mq_init_allocated_queue() for … | Aug 26, 2026 |
| CVE-2026-80588 | HIGH | 7.5 | In the Linux kernel, the following vulnerability has been resolved: mptcp: reclaim forward-allocated memory on RX path errors After commit 9db5b3cec4ec ("mptcp: borrow forward memory … | Aug 26, 2026 |
| CVE-2026-80587 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboptions Some MPTCP suboptions are mutually exclusive according to the … | Aug 26, 2026 |
| CVE-2026-80586 | CRITICAL | 9.8 | In the Linux kernel, the following vulnerability has been resolved: mptcp: options: reset DSS fields in case of unexpected size A remote peer could send … | Aug 26, 2026 |
| CVE-2026-80585 | CRITICAL | 9.4 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with SYN data Passive TCP Fast Open accepts a … | Aug 26, 2026 |
| CVE-2026-80584 | HIGH | 8.4 | In the Linux kernel, the following vulnerability has been resolved: s390/qeth: validate user buffer length in SNMP and ARP query ioctls qeth_snmp_command() and qeth_l3_arp_query() allocate … | Aug 26, 2026 |
| CVE-2026-80583 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses The "DEC0 MODE" to "DEC7 MODE" controls are … | Aug 26, 2026 |
| CVE-2026-80582 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: drm/shmem_helper: Check VMA boundaries for PMD mappings In the ->huge_fault handler do not install a … | Aug 26, 2026 |
| CVE-2026-80581 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout Ignore IPC errors … | Aug 26, 2026 |
| CVE-2026-80580 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: fbdev: bound mode sysfs output to the sysfs buffer mode_string() uses snprintf() which can return … | Aug 26, 2026 |