Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

43670
Total
3528
Critical
13050
High
12909
Medium
CVE ID Severity Score Description Published
CVE-2026-81033 MEDIUM 5.3 Automatisch reveals whether an address is registered through the response to its forgot-password request. The controller at packages/backend/src/controllers/internal/api/v1/users/forgot-password.js looks the address up and chains a … Aug 26, 2026
CVE-2026-81032 CRITICAL 9.8 NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all … Aug 26, 2026
CVE-2026-81031 HIGH 7.2 IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the request. The update handler in backend/src/controllers/middlewaresControllers/createUserController/updatePassword.js resolves … Aug 26, 2026
CVE-2026-81030 MEDIUM 6.5 Mage AI does not confine the paths accepted by its browser-items API to the project directory. BrowserItemResource in mage_ai/api/resources/BrowserItemResource.py passes a caller-supplied path to the … Aug 26, 2026
CVE-2026-81029 HIGH 8.1 OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the … Aug 26, 2026
CVE-2026-81028 MEDIUM 4.9 ZLMediaKit confines the downloadFile API to a configured set of root directories with a prefix comparison that does not account for directory boundaries. The configuration … Aug 26, 2026
CVE-2026-81027 HIGH 8.5 one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a specific channel either through a suffix … Aug 26, 2026
CVE-2026-80428 CRITICAL 9.8 ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIAS/AuthShibboleth/resources/shib_logout.php runs in a context that ilInitialisation exempts from authentication, and … Aug 26, 2026
CVE-2026-80427 HIGH 8.4 bestzip builds the argument list for the system zip utility without separating options from operands. The destination archive path and the caller-supplied source paths are … Aug 26, 2026
CVE-2026-80426 HIGH 7.1 FiftyOne renders a dataset field's description as markup. The sidebar field-information component at app/packages/core/src/components/FieldLabelAndInfo/index.tsx passes the description string to React's dangerouslySetInnerHTML, and no layer between … Aug 26, 2026
CVE-2026-54614 MEDIUM 4.3 DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feature in src/Controller/MailPreviewController.php accepts a route-controlled previewName value in … Aug 26, 2026
CVE-2026-54606 UNKNOWN SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 3.1.4, the SunEditor Embed plugin in src/plugins/modal/embed.js parses attacker-controlled … Aug 26, 2026
CVE-2026-54569 CRITICAL 9.8 SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution … Aug 26, 2026
CVE-2026-48549 MEDIUM 6.5 Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi. When no Cookie header is present, the double-submit cookie protection … Aug 26, 2026
CVE-2026-48548 MEDIUM 6.5 Nagios Core before 4.5.12 contains a cross-site request forgery vulnerability in cmd.cgi where the CSRF protection mechanism passes validation when the NagFormId cookie is absent. … Aug 26, 2026
CVE-2026-80589 CRITICAL 9.8 In the Linux kernel, the following vulnerability has been resolved: block: stop the timeout timer when releasing a never added disk disk_release() undoes blk_mq_init_allocated_queue() for … Aug 26, 2026
CVE-2026-80588 HIGH 7.5 In the Linux kernel, the following vulnerability has been resolved: mptcp: reclaim forward-allocated memory on RX path errors After commit 9db5b3cec4ec ("mptcp: borrow forward memory … Aug 26, 2026
CVE-2026-80587 CRITICAL 9.8 In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboptions Some MPTCP suboptions are mutually exclusive according to the … Aug 26, 2026
CVE-2026-80586 CRITICAL 9.8 In the Linux kernel, the following vulnerability has been resolved: mptcp: options: reset DSS fields in case of unexpected size A remote peer could send … Aug 26, 2026
CVE-2026-80585 CRITICAL 9.4 In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with SYN data Passive TCP Fast Open accepts a … Aug 26, 2026
CVE-2026-80584 HIGH 8.4 In the Linux kernel, the following vulnerability has been resolved: s390/qeth: validate user buffer length in SNMP and ARP query ioctls qeth_snmp_command() and qeth_l3_arp_query() allocate … Aug 26, 2026
CVE-2026-80583 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses The "DEC0 MODE" to "DEC7 MODE" controls are … Aug 26, 2026
CVE-2026-80582 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: drm/shmem_helper: Check VMA boundaries for PMD mappings In the ->huge_fault handler do not install a … Aug 26, 2026
CVE-2026-80581 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout Ignore IPC errors … Aug 26, 2026
CVE-2026-80580 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: fbdev: bound mode sysfs output to the sysfs buffer mode_string() uses snprintf() which can return … Aug 26, 2026