Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44710
Total
3597
Critical
13280
High
13130
Medium
CVE ID Severity Score Description Published
CVE-2026-75803 UNKNOWN Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by … Aug 25, 2026
CVE-2026-63076 HIGH 7.5 Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it … Aug 25, 2026
CVE-2026-63075 HIGH 7.5 Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain … Aug 25, 2026
CVE-2026-63074 MEDIUM 5.9 Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they … Aug 25, 2026
CVE-2026-63073 UNKNOWN Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or … Aug 25, 2026
CVE-2026-63072 HIGH 7.5 Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and … Aug 25, 2026
CVE-2026-57863 HIGH 8.8 Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended … Aug 25, 2026
CVE-2026-54874 HIGH 7.5 Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the … Aug 25, 2026
CVE-2026-18798 HIGH 7.5 Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads … Aug 25, 2026
CVE-2026-14457 HIGH 7.5 Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured … Aug 25, 2026
CVE-2026-79673 MEDIUM 6.5 Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:read scope, a read-only scope, but allows write operations including password changes. An attacker with … Aug 25, 2026
CVE-2026-79672 MEDIUM 5.5 Ech0 before 4.4.3 fails to enforce scope-based authorization on nine comment panel admin endpoints, allowing access tokens with minimal scopes to perform full comment moderation … Aug 25, 2026
CVE-2026-79671 MEDIUM 5.5 Ech0 through 4.2.1 contains a server-side request forgery vulnerability in the validateWebhookURL function (webhook_setting_service.go), which only validates literal IP addresses via net.ParseIP() and fails to … Aug 25, 2026
CVE-2026-79670 MEDIUM 4.8 Ech0 before 4.4.3 contains a stored cross-site scripting vulnerability in the file upload endpoint that validates Content-Type using only client-supplied headers without server-side inspection. Attackers … Aug 25, 2026
CVE-2026-79669 MEDIUM 4.3 Ech0 before 4.4.3 lacks authorization checks on system log endpoints allowing any authenticated non-admin user to read and stream all server logs. Attackers can access … Aug 25, 2026
CVE-2026-79668 MEDIUM 5.3 Ech0 before 4.7.3 contains an authentication bypass vulnerability in the PUT /api/echo/like/:id endpoint that allows unauthenticated attackers to increment engagement metrics without identity verification or … Aug 25, 2026
CVE-2026-79667 HIGH 7.6 Ech0 version 4.3.4 and earlier fails to reliably enforce scoped access token (least-privilege) restrictions on several privileged admin routes. Multiple privileged endpoints (e.g., /api/inbox, /api/panel/comments, … Aug 25, 2026
CVE-2026-79666 MEDIUM 6.5 Ech0 before 4.4.3 fails to enforce administrator authorization on dashboard log endpoints, allowing any authenticated user to access system logs. Attackers with valid user sessions … Aug 25, 2026
CVE-2026-79665 HIGH 8.8 Ech0 before 4.5.1 contains an authorization bypass vulnerability where session tokens skip scope validation in RequireScopes middleware, allowing logged-in non-admin users to access admin endpoints. … Aug 25, 2026
CVE-2026-79664 HIGH 7.4 Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintain perpetual authenticated access after token theft. Three independent … Aug 25, 2026
CVE-2026-79663 MEDIUM 4.8 Ech0 before 4.7.3 contains a stored cross-site scripting vulnerability in the public RSS feed where tag names and markdown content are rendered without HTML escaping. … Aug 25, 2026
CVE-2026-79662 HIGH 8.0 Ech0 through 4.5.6 contains an OAuth redirect URI validation vulnerability in parseAndValidateClientRedirect (internal/service/auth/auth.go) that compares only the scheme and host of the client-supplied redirect_uri against … Aug 25, 2026
CVE-2026-79661 MEDIUM 6.5 Ech0 through 4.5.6 registers the PUT /api/echo/like/:id endpoint on the public router group without authentication or rate limiting. Unauthenticated attackers can increment the fav_count counter … Aug 25, 2026
CVE-2026-79660 MEDIUM 5.3 Ech0 versions before 4.7.3 expose guest commenter email addresses through public API endpoints due to improper JSON serialization tags on the Comment model. Unauthenticated attackers … Aug 25, 2026
CVE-2026-79659 HIGH 7.7 Ech0 before 4.7.3 contains a server-side request forgery vulnerability in the fetchPeerConnectInfo function that uses unvalidated HTTP requests instead of safe request methods with URL … Aug 25, 2026