Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44043
Total
3569
Critical
13212
High
13018
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-75370 | UNKNOWN | — | An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via … | Aug 24, 2026 |
| CVE-2026-71832 | UNKNOWN | — | Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial … | Aug 24, 2026 |
| CVE-2026-71509 | MEDIUM | 6.5 | Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint that allows authenticated attackers with expense-creation rights to bypass … | Aug 24, 2026 |
| CVE-2026-71508 | MEDIUM | 6.5 | Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields … | Aug 24, 2026 |
| CVE-2026-71507 | MEDIUM | 6.5 | Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation … | Aug 24, 2026 |
| CVE-2026-71506 | HIGH | 8.1 | Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete … | Aug 24, 2026 |
| CVE-2026-71505 | HIGH | 7.1 | Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation … | Aug 24, 2026 |
| CVE-2026-71504 | HIGH | 8.1 | Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of … | Aug 24, 2026 |
| CVE-2026-71503 | MEDIUM | 6.1 | Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding … | Aug 24, 2026 |
| CVE-2026-40877 | HIGH | 8.7 | Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which … | Aug 24, 2026 |
| CVE-2026-39975 | UNKNOWN | — | Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code … | Aug 24, 2026 |
| CVE-2026-30864 | HIGH | 8.9 | Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. … | Aug 24, 2026 |
| CVE-2026-13081 | UNKNOWN | — | Rejected reason: Red Hat is not the CNA for PHP. CVE was reserved in error; the appropriate CNA should assign CVE IDs for these vulnerabilities. | Aug 24, 2026 |
| CVE-2026-13047 | UNKNOWN | — | Rejected reason: Red Hat is not the CNA for PHP. CVE was reserved in error; the appropriate CNA should assign CVE IDs for these vulnerabilities. | Aug 24, 2026 |
| CVE-2025-26238 | UNKNOWN | — | In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code. | Aug 24, 2026 |
| CVE-2025-26237 | UNKNOWN | — | D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can be exploited to run arbitrary commands. | Aug 24, 2026 |
| CVE-2026-9254 | UNKNOWN | — | An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering … | Aug 24, 2026 |
| CVE-2026-78475 | MEDIUM | 6.1 | A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array … | Aug 24, 2026 |
| CVE-2026-76838 | HIGH | 8.5 | Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule.php resolves the hostname with gethostbyname() and rejects … | Aug 24, 2026 |
| CVE-2026-76837 | MEDIUM | 6.4 | Baserow interpolates a user's display name into the rich-text mention markup without HTML encoding. PATCH /api/user/account/ stores the first_name value verbatim, and the mention renderer … | Aug 24, 2026 |
| CVE-2026-76836 | HIGH | 8.8 | AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is annotated … | Aug 24, 2026 |
| CVE-2026-76835 | CRITICAL | 9.1 | OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the … | Aug 24, 2026 |
| CVE-2026-76073 | HIGH | 8.8 | Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset … | Aug 24, 2026 |
| CVE-2026-76072 | HIGH | 7.4 | The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running unattended. In headless mode and auto mode the … | Aug 24, 2026 |
| CVE-2026-71982 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 24, 2026 |