Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25817
Total
1927
Critical
7883
High
8141
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-51218 | MEDIUM | 6.5 | A heap buffer overflow in the TS7Worker::PerformFunctionWrite() function (/core/s7_server.cpp) of snap7 v1.4.3 allows attackers to cause a Denial of Service (DoS) via a crafted packet. | Jun 29, 2026 |
| CVE-2026-10648 | MEDIUM | 6.2 | mcumgr_serial_process_frag() in subsys/mgmt/mcumgr/transport/src/serial_util.c calls net_buf_reset() on the result of smp_packet_alloc() before checking it for NULL. smp_packet_alloc() uses net_buf_alloc(K_NO_WAIT) against the shared MCUmgr packet pool (CONFIG_MCUMGR_TRANSPORT_NETBUF_COUNT, … | Jun 29, 2026 |
| CVE-2026-57997 | MEDIUM | 4.8 | Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not explicitly configured, allowing acceptance of HS384 and HS512 tokens alongside HS256. Attackers possessing … | Jun 29, 2026 |
| CVE-2026-51221 | HIGH | 7.5 | A buffer overflow in the Get_Attribute_List function of EIPStackGroup OpENer commit 76b95c allows attackers to cause a Denial of Service (DoS) via supplying a crafted … | Jun 29, 2026 |
| CVE-2026-34592 | HIGH | 7.7 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, Coolify server and project lookups are not scoped to … | Jun 29, 2026 |
| CVE-2026-10647 | MEDIUM | 5.3 | The USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c) ignores the return value of usbd_ep_enqueue() in its ethernet transmit callback cdc_ncm_send(). When the enqueue fails, the function still … | Jun 29, 2026 |
| CVE-2026-55957 | HIGH | 7.3 | Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided … | Jun 29, 2026 |
| CVE-2026-55956 | MEDIUM | 6.5 | Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of … | Jun 29, 2026 |
| CVE-2026-55955 | MEDIUM | 6.5 | Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through … | Jun 29, 2026 |
| CVE-2026-55276 | CRITICAL | 9.1 | Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. … | Jun 29, 2026 |
| CVE-2026-53434 | CRITICAL | 9.1 | Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 … | Jun 29, 2026 |
| CVE-2026-53404 | HIGH | 7.3 | Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were … | Jun 29, 2026 |
| CVE-2026-50229 | MEDIUM | 6.1 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache … | Jun 29, 2026 |
| CVE-2026-41896 | HIGH | 7.5 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the HMAC key is the application's manual_webhook_secret_github field, which … | Jun 29, 2026 |
| CVE-2026-34597 | HIGH | 8.8 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.470, a critical Authenticated Host Remote Code Execution (RCE) vulnerability … | Jun 29, 2026 |
| CVE-2026-34594 | HIGH | 8.8 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, an authenticated command injection vulnerability in the Destination Network … | Jun 29, 2026 |
| CVE-2026-13758 | LOW | 3.7 | CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt_done path. The decrypt_done($tag) form compares it against the … | Jun 29, 2026 |
| CVE-2026-57919 | HIGH | 7.8 | PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ and GENERIC_WRITE permissions to … | Jun 29, 2026 |
| CVE-2026-57498 | CRITICAL | 9.6 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) … | Jun 29, 2026 |
| CVE-2026-56018 | HIGH | 7.5 | JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory growth. In JsMinify (XS.xs) the cleanup frees only the … | Jun 29, 2026 |
| CVE-2026-56017 | HIGH | 7.5 | JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful token of the input is a slash. The regexp … | Jun 29, 2026 |
| CVE-2026-54889 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in leandrocp mdex allows cross-site scripting via unsanitized URL schemes in Quill Delta output. 'Elixir.MDEx':to_delta/2 … | Jun 29, 2026 |
| CVE-2026-54888 | UNKNOWN | — | Uncontrolled Recursion vulnerability in leandrocp mdex allows denial of service via deeply nested Markdown input. mdex converts between an Elixir %MDEx.Document{} struct and Comrak's internal … | Jun 29, 2026 |
| CVE-2026-53429 | UNKNOWN | — | Missing Release of Memory after Effective Lifetime vulnerability in leandrocp mdex and mdex_native allows an attacker who controls a rendered document to cause a denial … | Jun 29, 2026 |
| CVE-2026-53426 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling vulnerability in leandrocp MDEx allows Excessive Allocation. MDEx.parse_document/2 accepts a {:json, json} source. In lib/mdex.ex, the private json_to_node/1 … | Jun 29, 2026 |