Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44043
Total
3569
Critical
13212
High
13018
Medium
CVE ID Severity Score Description Published
CVE-2025-68825 HIGH 7.5 HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, container breakout, and interception of sensitive internal communications. Aug 24, 2026
CVE-2026-9728 MEDIUM 6.4 The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out of live userspace memory, and then forwarded the … Aug 24, 2026
CVE-2026-78414 HIGH 8.0 Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux, Windows and MacOS allows an adjacent-network attacker … Aug 24, 2026
CVE-2026-78391 UNKNOWN RansomLook contains a stored cross-site scripting (XSS) vulnerability in the cryptocurrency wallet detail view. Cryptocurrency addresses and blockchain names originating from external sources, including the … Aug 24, 2026
CVE-2026-78387 UNKNOWN RansomLook contains an authorization weakness in the web-based configuration editor exposed through the /admin/config endpoint. The endpoint requires an authenticated session but does not perform … Aug 24, 2026
CVE-2026-76055 UNKNOWN Improper Neutralization of Special Elements used in an OS Command in the package manager component of Black Duck blackduck-c-cpp before 3.0.7 allows an actor able … Aug 24, 2026
CVE-2026-76054 UNKNOWN Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute code within the scanned project's … Aug 24, 2026
CVE-2026-65053 MEDIUM 6.1 Horde IMP's AppleDouble MIME viewer writes an attacker-controlled attachment name into an HTML status block without escaping it. In lib/Mime/Viewer/Appledouble.php, _IMPrender() obtains the name of … Aug 24, 2026
CVE-2026-39915 HIGH 8.1 TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to inject arbitrary HTTP headers and response body content by embedding unsanitized … Aug 24, 2026
CVE-2026-39914 MEDIUM 6.5 TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arbitrary SQL queries to a privileged dashboard Excel export … Aug 24, 2026
CVE-2026-21755 MEDIUM 5.3 HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or credential stuffing attacks, or cause a … Aug 24, 2026
CVE-2026-19874 CRITICAL 9.1 A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The … Aug 24, 2026
CVE-2026-78386 UNKNOWN RansomLook exposed sensitive operator-side scraping configuration through multiple unauthenticated API responses. Location records associated with ransomware groups and markets were returned largely verbatim to unauthenticated … Aug 24, 2026
CVE-2026-78385 UNKNOWN RansomLook contains insufficient resource validation in the analysis PDF generation functionality. Analysis documents are converted from Markdown to HTML and passed to WeasyPrint for PDF … Aug 24, 2026
CVE-2026-78381 UNKNOWN RansomLook contains a path traversal vulnerability in the handling of the screen field associated with group posts. The GroupPost.get API handler concatenates the database-controlled screen … Aug 24, 2026
CVE-2026-78380 UNKNOWN RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim posts to external notification channels. The post-processing logic … Aug 24, 2026
CVE-2026-78378 UNKNOWN Ransomlook contains a Redis glob pattern injection vulnerability caused by insufficient neutralization of user-controlled input before it is incorporated into Redis SCAN MATCH patterns. The … Aug 24, 2026
CVE-2026-78376 HIGH 8.8 A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption. Aug 24, 2026
CVE-2026-78372 UNKNOWN RansomLook does not consistently enforce authorization checks when accessing groups, markets, and ransom notes marked as private. An unauthenticated or otherwise unauthorized remote attacker can … Aug 24, 2026
CVE-2026-78370 UNKNOWN RansomLook contains an authorization flaw in its legacy database export functionality that can allow unauthenticated remote users to retrieve information intended to remain private. The … Aug 24, 2026
CVE-2026-78369 UNKNOWN RansomLook contains a missing authentication vulnerability in the /admin/crypto/group/new endpoint. While the endpoint provides an administrative function for creating new crypto group entries, it was … Aug 24, 2026
CVE-2026-78367 HIGH 7.0 A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive … Aug 24, 2026
CVE-2026-78250 MEDIUM 4.3 A vulnerability was identified in bytebot-ai bytebot 0.0.1. The affected element is an unknown function of the component Agent Execution Workflow. Such manipulation leads to … Aug 24, 2026
CVE-2026-78248 HIGH 7.3 A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/ajax.php?action=save_settings. This manipulation of the … Aug 24, 2026
CVE-2026-77995 UNKNOWN Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login … Aug 24, 2026