Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44043
Total
3569
Critical
13212
High
13018
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-75099 | MEDIUM | 5.3 | Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through 1.19.1. Users are recommended to upgrade to version 1.20.0, … | Aug 24, 2026 |
| CVE-2026-71300 | UNKNOWN | — | Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 … | Aug 24, 2026 |
| CVE-2026-66908 | UNKNOWN | — | Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.22.0. The camel-main embedded HTTP server can … | Aug 24, 2026 |
| CVE-2026-66907 | UNKNOWN | — | Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 … | Aug 24, 2026 |
| CVE-2026-66906 | UNKNOWN | — | Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from … | Aug 24, 2026 |
| CVE-2026-63621 | UNKNOWN | — | Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Knative component The Knative consumer … | Aug 24, 2026 |
| CVE-2026-60093 | UNKNOWN | — | Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 … | Aug 24, 2026 |
| CVE-2026-59230 | UNKNOWN | — | Improper input validation vulnerability in Apache Camel. This issue affects Apache Camel: from 2.17.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The … | Aug 24, 2026 |
| CVE-2026-19685 | HIGH | 7.1 | NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user … | Aug 24, 2026 |
| CVE-2026-18349 | UNKNOWN | — | Improper protection against voltage and clock glitches vulnerability in Microchip SAMA5D4 allows Hardware Fault Injection. This issue affects SAMA5D4. | Aug 24, 2026 |
| CVE-2026-15469 | UNKNOWN | — | The use of hard-coded cryptographic key vulnerability has been identified in the mesh functionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6. A shared … | Aug 24, 2026 |
| CVE-2025-36940 | HIGH | 8.8 | Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from Userspace to Kernel (AP) | Aug 24, 2026 |
| CVE-2025-36939 | UNKNOWN | — | Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a … | Aug 24, 2026 |
| CVE-2026-78416 | UNKNOWN | — | Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. … | Aug 24, 2026 |
| CVE-2026-76071 | CRITICAL | 9.8 | Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized … | Aug 24, 2026 |
| CVE-2026-76070 | CRITICAL | 9.8 | Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized … | Aug 24, 2026 |
| CVE-2026-71366 | HIGH | 7.7 | A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs … | Aug 24, 2026 |
| CVE-2026-71364 | HIGH | 7.2 | A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts zip and tar archive members by joining the project … | Aug 24, 2026 |
| CVE-2026-67204 | MEDIUM | 5.4 | BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by … | Aug 24, 2026 |
| CVE-2026-21752 | HIGH | 7.5 | HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or compromise of the system by exploiting … | Aug 24, 2026 |
| CVE-2026-13343 | MEDIUM | 5.3 | The UMP Stream responder library in lib/midi2/ump_stream_responder.c builds reply packets in a 16-byte struct midi_ump (uint32_t data[4]). The builders make_endpoint_info() and make_function_block_info() populate only the … | Aug 24, 2026 |
| CVE-2026-13212 | HIGH | 8.8 | The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device writes into the used ring. In virtio_isr() (drivers/virtio/virtio_common.c), the device-written … | Aug 24, 2026 |
| CVE-2026-12556 | UNKNOWN | — | Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. … | Aug 24, 2026 |
| CVE-2026-12555 | UNKNOWN | — | Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. … | Aug 24, 2026 |
| CVE-2026-12554 | UNKNOWN | — | Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. … | Aug 24, 2026 |