Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44043
Total
3569
Critical
13212
High
13018
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-68825 | HIGH | 7.5 | HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, container breakout, and interception of sensitive internal communications. | Aug 24, 2026 |
| CVE-2026-9728 | MEDIUM | 6.4 | The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out of live userspace memory, and then forwarded the … | Aug 24, 2026 |
| CVE-2026-78414 | HIGH | 8.0 | Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux, Windows and MacOS allows an adjacent-network attacker … | Aug 24, 2026 |
| CVE-2026-78391 | UNKNOWN | — | RansomLook contains a stored cross-site scripting (XSS) vulnerability in the cryptocurrency wallet detail view. Cryptocurrency addresses and blockchain names originating from external sources, including the … | Aug 24, 2026 |
| CVE-2026-78387 | UNKNOWN | — | RansomLook contains an authorization weakness in the web-based configuration editor exposed through the /admin/config endpoint. The endpoint requires an authenticated session but does not perform … | Aug 24, 2026 |
| CVE-2026-76055 | UNKNOWN | — | Improper Neutralization of Special Elements used in an OS Command in the package manager component of Black Duck blackduck-c-cpp before 3.0.7 allows an actor able … | Aug 24, 2026 |
| CVE-2026-76054 | UNKNOWN | — | Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute code within the scanned project's … | Aug 24, 2026 |
| CVE-2026-65053 | MEDIUM | 6.1 | Horde IMP's AppleDouble MIME viewer writes an attacker-controlled attachment name into an HTML status block without escaping it. In lib/Mime/Viewer/Appledouble.php, _IMPrender() obtains the name of … | Aug 24, 2026 |
| CVE-2026-39915 | HIGH | 8.1 | TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to inject arbitrary HTTP headers and response body content by embedding unsanitized … | Aug 24, 2026 |
| CVE-2026-39914 | MEDIUM | 6.5 | TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arbitrary SQL queries to a privileged dashboard Excel export … | Aug 24, 2026 |
| CVE-2026-21755 | MEDIUM | 5.3 | HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or credential stuffing attacks, or cause a … | Aug 24, 2026 |
| CVE-2026-19874 | CRITICAL | 9.1 | A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The … | Aug 24, 2026 |
| CVE-2026-78386 | UNKNOWN | — | RansomLook exposed sensitive operator-side scraping configuration through multiple unauthenticated API responses. Location records associated with ransomware groups and markets were returned largely verbatim to unauthenticated … | Aug 24, 2026 |
| CVE-2026-78385 | UNKNOWN | — | RansomLook contains insufficient resource validation in the analysis PDF generation functionality. Analysis documents are converted from Markdown to HTML and passed to WeasyPrint for PDF … | Aug 24, 2026 |
| CVE-2026-78381 | UNKNOWN | — | RansomLook contains a path traversal vulnerability in the handling of the screen field associated with group posts. The GroupPost.get API handler concatenates the database-controlled screen … | Aug 24, 2026 |
| CVE-2026-78380 | UNKNOWN | — | RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim posts to external notification channels. The post-processing logic … | Aug 24, 2026 |
| CVE-2026-78378 | UNKNOWN | — | Ransomlook contains a Redis glob pattern injection vulnerability caused by insufficient neutralization of user-controlled input before it is incorporated into Redis SCAN MATCH patterns. The … | Aug 24, 2026 |
| CVE-2026-78376 | HIGH | 8.8 | A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption. | Aug 24, 2026 |
| CVE-2026-78372 | UNKNOWN | — | RansomLook does not consistently enforce authorization checks when accessing groups, markets, and ransom notes marked as private. An unauthenticated or otherwise unauthorized remote attacker can … | Aug 24, 2026 |
| CVE-2026-78370 | UNKNOWN | — | RansomLook contains an authorization flaw in its legacy database export functionality that can allow unauthenticated remote users to retrieve information intended to remain private. The … | Aug 24, 2026 |
| CVE-2026-78369 | UNKNOWN | — | RansomLook contains a missing authentication vulnerability in the /admin/crypto/group/new endpoint. While the endpoint provides an administrative function for creating new crypto group entries, it was … | Aug 24, 2026 |
| CVE-2026-78367 | HIGH | 7.0 | A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive … | Aug 24, 2026 |
| CVE-2026-78250 | MEDIUM | 4.3 | A vulnerability was identified in bytebot-ai bytebot 0.0.1. The affected element is an unknown function of the component Agent Execution Workflow. Such manipulation leads to … | Aug 24, 2026 |
| CVE-2026-78248 | HIGH | 7.3 | A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/ajax.php?action=save_settings. This manipulation of the … | Aug 24, 2026 |
| CVE-2026-77995 | UNKNOWN | — | Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login … | Aug 24, 2026 |