Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25897
Total
1938
Critical
7913
High
8158
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-56285 | HIGH | 8.6 | Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthenticated attackers to compute … | Jun 29, 2026 |
| CVE-2026-36848 | HIGH | 7.5 | Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem. | Jun 29, 2026 |
| CVE-2026-13592 | HIGH | 7.3 | A vulnerability was detected in liftoff-sr CIPster up to e8e9dba09bf56962807d3504b783ccdb6287f3e4. Affected by this issue is the function BufWriter::append of the component EtherNet IP Message Handler. … | Jun 29, 2026 |
| CVE-2026-11720 | UNKNOWN | — | A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into … | Jun 29, 2026 |
| CVE-2026-13752 | MEDIUM | 6.0 | Improper neutralization of parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. An attacker could exploit this by supplying crafted values to … | Jun 29, 2026 |
| CVE-2026-13751 | MEDIUM | 4.1 | Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. The SQL statement reader's !source/!load directives could reference … | Jun 29, 2026 |
| CVE-2026-13591 | MEDIUM | 5.0 | A weakness has been identified in DeepMyst Mysti 0.4.0. Affected is the function _isTrackedConversation of the file src/managers/ChannelBridge.ts of the component Contact Tracking. This manipulation … | Jun 29, 2026 |
| CVE-2026-13590 | MEDIUM | 5.6 | A security flaw has been discovered in seladb PcapPlusPlus 25.05. This impacts the function pcpp::ModbusLayer::getLength in the library Packet++/header/ModbusLayer.h of the component Modbus Protocol Handler. … | Jun 29, 2026 |
| CVE-2026-13589 | MEDIUM | 5.6 | A vulnerability was identified in seladb PcapPlusPlus 25.05. This affects the function pcpp::TelnetLayer::getSubCommand of the file Packet++/src/TelnetLayer.cpp of the component Telnet Subnegotiation Packet Handler. The … | Jun 29, 2026 |
| CVE-2026-13588 | MEDIUM | 5.6 | A vulnerability was determined in seladb PcapPlusPlus 25.05. The impacted element is the function pcpp::SSLClientHelloMessage::getHandshakeVersion of the file Packet++/src/SSLHandshake.cpp of the component TLS Hello Handler. … | Jun 29, 2026 |
| CVE-2026-12912 | HIGH | 7.3 | A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when … | Jun 29, 2026 |
| CVE-2026-12672 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this … | Jun 29, 2026 |
| CVE-2026-9105 | UNKNOWN | — | An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafted HTTP requests … | Jun 29, 2026 |
| CVE-2026-41052 | UNKNOWN | — | Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and … | Jun 29, 2026 |
| CVE-2026-13750 | MEDIUM | 5.5 | Insertion of sensitive information into log files in Snowflake CLI versions prior to 3.19 allowed plaintext credentials to be written to persistent local debug logs. … | Jun 29, 2026 |
| CVE-2026-13749 | HIGH | 8.8 | Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI versions prior to 3.19 allowed arbitrary code execution during application bundling or deployment. … | Jun 29, 2026 |
| CVE-2026-13748 | MEDIUM | 6.3 | Improper restriction of file path resolution in Snowflake CLI versions prior to 3.19 allowed arbitrary local file content to be read and transmitted to Snowflake … | Jun 29, 2026 |
| CVE-2026-13746 | LOW | 3.6 | Improper neutralization of local CLI parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. A user could trigger this issue by supplying … | Jun 29, 2026 |
| CVE-2026-13744 | HIGH | 8.3 | Improper neutralization of attacker-controlled content in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. By supplying crafted repository content, project configuration, manifest data, … | Jun 29, 2026 |
| CVE-2026-13742 | UNKNOWN | — | Honeywell IQ MultiAccess, all versions prior to and including version 28, contain an improper digital signature verification vulnerability. An attacker could potentially exploit this vulnerability, … | Jun 29, 2026 |
| CVE-2026-13587 | LOW | 3.7 | A vulnerability was found in seladb PcapPlusPlus 25.05. The affected element is the function parse_by_block_type of the file light_pcapng.c of the component LightPcapNg Parser. Performing … | Jun 29, 2026 |
| CVE-2026-13583 | HIGH | 8.8 | A vulnerability has been found in Edimax EW-7478APC 1.04. Impacted is the function formUSBFolder of the file /goform/formUSBFolder of the component POST Request Handler. Such … | Jun 29, 2026 |
| CVE-2026-13582 | HIGH | 8.8 | A flaw has been found in Edimax EW-7478APC 1.04. This issue affects the function formUSBAccount of the file /goform/formUSBAccount of the component POST Request Handler. … | Jun 29, 2026 |
| CVE-2026-13581 | MEDIUM | 6.3 | A vulnerability was detected in Edimax EW-7478APC 1.04. This vulnerability affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. The … | Jun 29, 2026 |
| CVE-2026-13580 | HIGH | 8.8 | A security vulnerability has been detected in Edimax EW-7478APC 1.04. This affects the function formQoS of the file /goform/formQoS of the component POST Request Handler. … | Jun 29, 2026 |