Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44710
Total
3597
Critical
13280
High
13130
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-7455 | HIGH | 7.8 | A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to … | Aug 24, 2026 |
| CVE-2026-77635 | UNKNOWN | — | CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable … | Aug 24, 2026 |
| CVE-2026-77634 | UNKNOWN | — | CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers … | Aug 24, 2026 |
| CVE-2026-77567 | HIGH | 8.1 | Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication … | Aug 24, 2026 |
| CVE-2026-75554 | UNKNOWN | — | Insufficient Session Expiration vulnerability in the OAuth token refresh grant in hexpm hexpm allows a user removed from an organization to keep reading its private … | Aug 24, 2026 |
| CVE-2026-75542 | UNKNOWN | — | Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositories permission to read another organization's private packages. … | Aug 24, 2026 |
| CVE-2026-75464 | UNKNOWN | — | OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link(). | Aug 24, 2026 |
| CVE-2026-5006 | MEDIUM | 6.8 | A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated … | Aug 24, 2026 |
| CVE-2026-56136 | UNKNOWN | — | In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process … | Aug 24, 2026 |
| CVE-2026-56135 | UNKNOWN | — | In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/security.c that allows an attacker to corrupt heap memory in the … | Aug 24, 2026 |
| CVE-2026-55468 | MEDIUM | 4.3 | Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the … | Aug 24, 2026 |
| CVE-2026-52492 | UNKNOWN | — | An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based … | Aug 24, 2026 |
| CVE-2026-52490 | UNKNOWN | — | An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c | Aug 24, 2026 |
| CVE-2026-19568 | HIGH | 7.8 | A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to … | Aug 24, 2026 |
| CVE-2026-16783 | HIGH | 7.8 | A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to … | Aug 24, 2026 |
| CVE-2026-16782 | MEDIUM | 5.3 | A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to … | Aug 24, 2026 |
| CVE-2026-16781 | MEDIUM | 5.5 | A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to … | Aug 24, 2026 |
| CVE-2022-30983 | UNKNOWN | — | A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the … | Aug 24, 2026 |
| CVE-2026-78555 | UNKNOWN | — | RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Although the interface displayed only a shortened representation of each … | Aug 24, 2026 |
| CVE-2026-78553 | UNKNOWN | — | RansomLook created its Flask session-signing key without explicitly restricting the file permissions. The secret_key file was created using the process's default permissions and umask, resulting … | Aug 24, 2026 |
| CVE-2026-78551 | UNKNOWN | — | RansomLook contains multiple weaknesses in its authentication endpoint that allow an unauthenticated remote attacker to enumerate valid usernames, perform unrestricted password-guessing attacks, and potentially exhaust … | Aug 24, 2026 |
| CVE-2026-78430 | MEDIUM | 5.3 | A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall of the file src/tools/handlers.ts of the component Tool Handler. The manipulation of … | Aug 24, 2026 |
| CVE-2026-77923 | MEDIUM | 4.3 | Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the private-project membership check within the clonetasks mass action … | Aug 24, 2026 |
| CVE-2026-77310 | MEDIUM | 5.3 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release … | Aug 24, 2026 |
| CVE-2026-76816 | LOW | 3.5 | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH … | Aug 24, 2026 |