Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43670
Total
3528
Critical
13050
High
12909
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-19271 | HIGH | 7.5 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows LDAP Injection. This … | Aug 26, 2026 |
| CVE-2026-18252 | HIGH | 7.3 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain … | Aug 26, 2026 |
| CVE-2026-15990 | HIGH | 7.5 | The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.0.1 via the 'frm_graph' parameter. This makes … | Aug 26, 2026 |
| CVE-2026-15387 | MEDIUM | 4.3 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain … | Aug 26, 2026 |
| CVE-2026-12717 | UNKNOWN | — | An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service versions prior to 2026-05-01 on Google Cloud Platform … | Aug 26, 2026 |
| CVE-2025-10903 | MEDIUM | 6.5 | GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain … | Aug 26, 2026 |
| CVE-2026-79619 | UNKNOWN | — | On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real host privilege, allowing an … | Aug 26, 2026 |
| CVE-2026-77658 | HIGH | 7.8 | A stack-based buffer overflow vulnerability exists in the Dia diagram editor when processing Network Bus objects from Dia XML project files. In objects/network/bus.c, bus_load() reads … | Aug 26, 2026 |
| CVE-2026-12587 | UNKNOWN | — | The vulnerability allows the unauthorised generation of physical access QR codes due to the use of hard-coded credentials within the application. The generation mechanism uses … | Aug 26, 2026 |
| CVE-2026-63041 | UNKNOWN | — | Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attacker to escalate privilege or perform an authorization bypass … | Aug 26, 2026 |
| CVE-2026-15985 | HIGH | 8.1 | The Classified Listing - Mobile Number Verification plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.6.0. This is … | Aug 26, 2026 |
| CVE-2026-80206 | MEDIUM | 5.9 | NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep_node_action function compiles user-supplied regular expressions embedded in … | Aug 26, 2026 |
| CVE-2026-80205 | HIGH | 7.5 | NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSearcher.findall() methods that accept user-supplied regular expressions without validation or … | Aug 26, 2026 |
| CVE-2026-80204 | MEDIUM | 5.4 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 does not apply the API-key scope cap in the injectSecurityTab() function of BlueprintController when deciding whether a page's … | Aug 26, 2026 |
| CVE-2026-80203 | CRITICAL | 9.8 | The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses isSuperAdmin() … | Aug 26, 2026 |
| CVE-2026-77557 | CRITICAL | 9.8 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on … | Aug 26, 2026 |
| CVE-2026-77554 | CRITICAL | 10.0 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection … | Aug 26, 2026 |
| CVE-2026-77553 | CRITICAL | 9.9 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate … | Aug 26, 2026 |
| CVE-2026-77552 | CRITICAL | 9.8 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Video Bridge to execute a Command … | Aug 26, 2026 |
| CVE-2026-77551 | CRITICAL | 9.0 | A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Connect Display Cast … | Aug 26, 2026 |
| CVE-2026-77550 | CRITICAL | 10.0 | A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to … | Aug 26, 2026 |
| CVE-2026-77549 | CRITICAL | 9.0 | A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices … | Aug 26, 2026 |
| CVE-2026-77548 | CRITICAL | 9.9 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute … | Aug 26, 2026 |
| CVE-2026-77547 | CRITICAL | 9.9 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute … | Aug 26, 2026 |
| CVE-2026-77546 | CRITICAL | 9.9 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute … | Aug 26, 2026 |