Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25817
Total
1927
Critical
7883
High
8141
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-43706 | MEDIUM | 6.5 | A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously … | Jun 29, 2026 |
| CVE-2026-43705 | HIGH | 8.8 | A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing … | Jun 29, 2026 |
| CVE-2026-43704 | MEDIUM | 5.3 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A … | Jun 29, 2026 |
| CVE-2026-43703 | MEDIUM | 6.5 | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web … | Jun 29, 2026 |
| CVE-2026-43701 | HIGH | 8.3 | The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious website … | Jun 29, 2026 |
| CVE-2026-43700 | MEDIUM | 6.5 | A cross-origin issue was addressed with improved tracking of security origins. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe … | Jun 29, 2026 |
| CVE-2026-43699 | MEDIUM | 6.5 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing … | Jun 29, 2026 |
| CVE-2026-43676 | MEDIUM | 6.5 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. … | Jun 29, 2026 |
| CVE-2026-43663 | MEDIUM | 6.5 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously … | Jun 29, 2026 |
| CVE-2026-39872 | MEDIUM | 6.5 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously … | Jun 29, 2026 |
| CVE-2026-39868 | CRITICAL | 9.1 | This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be … | Jun 29, 2026 |
| CVE-2026-37637 | CRITICAL | 9.1 | An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component | Jun 29, 2026 |
| CVE-2026-31016 | MEDIUM | 6.5 | Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the IdentityServer account profile endpoint | Jun 29, 2026 |
| CVE-2026-28979 | MEDIUM | 6.5 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. … | Jun 29, 2026 |
| CVE-2026-13763 | CRITICAL | 9.8 | Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body … | Jun 29, 2026 |
| CVE-2026-13762 | CRITICAL | 9.8 | Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via … | Jun 29, 2026 |
| CVE-2026-13593 | MEDIUM | 6.5 | CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away. The minify function has a memory leak when … | Jun 29, 2026 |
| CVE-2026-13008 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-57700. Reason: This candidate is a reservation duplicate of CVE-2026-57700. Notes: All CVE … | Jun 29, 2026 |
| CVE-2026-58000 | HIGH | 8.8 | luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_meta parameter is interpolated into a … | Jun 29, 2026 |
| CVE-2026-57999 | HIGH | 8.8 | luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows authenticated users to execute arbitrary commands as root. The vulnerability exists because … | Jun 29, 2026 |
| CVE-2026-53428 | UNKNOWN | — | Memory Allocation with Excessive Size Value vulnerability in leandrocp mdex allows an unauthenticated attacker to cause a denial of service through unbounded memory allocation. comrak_nif::lumis_adapter::LumisAdapter::parse_highlight_lines … | Jun 29, 2026 |
| CVE-2026-53427 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leandrocp MDEx allows stored or reflected cross-site scripting via attacker-controlled Markdown. When syntax … | Jun 29, 2026 |
| CVE-2026-13757 | MEDIUM | 6.2 | A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit … | Jun 29, 2026 |
| CVE-2026-57960 | MEDIUM | 6.5 | Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated access to retrieve full attendee lists including emails and personal … | Jun 29, 2026 |
| CVE-2026-57959 | MEDIUM | 5.9 | Hi.Events through 1.9.0 contains a promo code validation vulnerability where reservation validates usage count before asynchronous UpdateEventStatisticsJob increments it, allowing attackers to redeem limited promo … | Jun 29, 2026 |