Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44043
Total
3569
Critical
13212
High
13018
Medium
CVE ID Severity Score Description Published
CVE-2026-75370 UNKNOWN An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via … Aug 24, 2026
CVE-2026-71832 UNKNOWN Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial … Aug 24, 2026
CVE-2026-71509 MEDIUM 6.5 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint that allows authenticated attackers with expense-creation rights to bypass … Aug 24, 2026
CVE-2026-71508 MEDIUM 6.5 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields … Aug 24, 2026
CVE-2026-71507 MEDIUM 6.5 Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation … Aug 24, 2026
CVE-2026-71506 HIGH 8.1 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete … Aug 24, 2026
CVE-2026-71505 HIGH 7.1 Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation … Aug 24, 2026
CVE-2026-71504 HIGH 8.1 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of … Aug 24, 2026
CVE-2026-71503 MEDIUM 6.1 Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding … Aug 24, 2026
CVE-2026-40877 HIGH 8.7 Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which … Aug 24, 2026
CVE-2026-39975 UNKNOWN Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code … Aug 24, 2026
CVE-2026-30864 HIGH 8.9 Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. … Aug 24, 2026
CVE-2026-13081 UNKNOWN Rejected reason: Red Hat is not the CNA for PHP. CVE was reserved in error; the appropriate CNA should assign CVE IDs for these vulnerabilities. Aug 24, 2026
CVE-2026-13047 UNKNOWN Rejected reason: Red Hat is not the CNA for PHP. CVE was reserved in error; the appropriate CNA should assign CVE IDs for these vulnerabilities. Aug 24, 2026
CVE-2025-26238 UNKNOWN In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code. Aug 24, 2026
CVE-2025-26237 UNKNOWN D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can be exploited to run arbitrary commands. Aug 24, 2026
CVE-2026-9254 UNKNOWN An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering … Aug 24, 2026
CVE-2026-78475 MEDIUM 6.1 A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array … Aug 24, 2026
CVE-2026-76838 HIGH 8.5 Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule.php resolves the hostname with gethostbyname() and rejects … Aug 24, 2026
CVE-2026-76837 MEDIUM 6.4 Baserow interpolates a user's display name into the rich-text mention markup without HTML encoding. PATCH /api/user/account/ stores the first_name value verbatim, and the mention renderer … Aug 24, 2026
CVE-2026-76836 HIGH 8.8 AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is annotated … Aug 24, 2026
CVE-2026-76835 CRITICAL 9.1 OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the … Aug 24, 2026
CVE-2026-76073 HIGH 8.8 Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset … Aug 24, 2026
CVE-2026-76072 HIGH 7.4 The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running unattended. In headless mode and auto mode the … Aug 24, 2026
CVE-2026-71982 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 24, 2026