Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43798
Total
3549
Critical
13122
High
12955
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-80195 | MEDIUM | 5.4 | Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /api/teams/{id}), which removes all existing team members … | Aug 26, 2026 |
| CVE-2026-80194 | MEDIUM | 4.3 | Kimai before 2.64.0 contains a missing authorization vulnerability in the ProjectViewController export route (report_project_view_export). The authorization guards are attached to the sibling __invoke method rather … | Aug 26, 2026 |
| CVE-2026-80193 | HIGH | 8.8 | Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create … | Aug 26, 2026 |
| CVE-2026-80192 | HIGH | 8.1 | @better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) contains two domain-ownership flaws. When domain verification … | Aug 26, 2026 |
| CVE-2026-80191 | HIGH | 7.5 | GROWI applies its page-viewer permission check to attachment requests only when the request carries an authenticated user. retrieveAttachmentFromIdParam in apps/app/src/server/routes/attachment/get.ts guards the check with a … | Aug 26, 2026 |
| CVE-2026-80189 | MEDIUM | 6.5 | LeafWiki extracts an uploaded ZIP archive without limiting how much data it will write. ZipExtractor.ExtractToDir in internal/importer/zip_extractor.go opens each entry and copies it to the … | Aug 26, 2026 |
| CVE-2026-76149 | MEDIUM | 4.4 | CorvusSKK contains an integer overflow vulnerability, which may allow malicious data to be written to a dictionary file. | Aug 26, 2026 |
| CVE-2026-76148 | HIGH | 7.8 | CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the affected product. | Aug 26, 2026 |
| CVE-2026-73335 | MEDIUM | 5.3 | Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A malicious application installed on the user's Android device … | Aug 26, 2026 |
| CVE-2026-58092 | MEDIUM | 5.4 | In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the … | Aug 26, 2026 |
| CVE-2026-58091 | HIGH | 7.8 | The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If locking a channel would block, it releases the … | Aug 26, 2026 |
| CVE-2026-58090 | HIGH | 7.8 | The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths … | Aug 26, 2026 |
| CVE-2026-58089 | HIGH | 7.8 | When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted check … | Aug 26, 2026 |
| CVE-2026-57171 | HIGH | 7.7 | Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, … | Aug 26, 2026 |
| CVE-2026-57170 | HIGH | 7.8 | Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom … | Aug 26, 2026 |
| CVE-2026-54467 | HIGH | 7.0 | On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer. | Aug 26, 2026 |
| CVE-2026-52776 | UNKNOWN | — | Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the URLSecurityValidator that guards trestle's … | Aug 26, 2026 |
| CVE-2026-29988 | HIGH | 7.6 | A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker … | Aug 26, 2026 |
| CVE-2026-19632 | CRITICAL | 9.8 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, … | Aug 26, 2026 |
| CVE-2026-80138 | CRITICAL | 9.8 | ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted … | Aug 25, 2026 |
| CVE-2026-79912 | HIGH | 8.3 | A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument … | Aug 25, 2026 |
| CVE-2026-79911 | CRITICAL | 10.0 | A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI … | Aug 25, 2026 |
| CVE-2026-70665 | MEDIUM | 4.2 | Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint … | Aug 25, 2026 |
| CVE-2026-55805 | MEDIUM | 5.4 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from … | Aug 25, 2026 |
| CVE-2026-54757 | HIGH | 7.8 | Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is … | Aug 25, 2026 |