Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44710
Total
3597
Critical
13280
High
13130
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-71503 | MEDIUM | 6.1 | Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding … | Aug 24, 2026 |
| CVE-2026-40877 | HIGH | 8.7 | Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which … | Aug 24, 2026 |
| CVE-2026-39975 | UNKNOWN | — | Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code … | Aug 24, 2026 |
| CVE-2026-30864 | HIGH | 8.9 | Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. … | Aug 24, 2026 |
| CVE-2026-13081 | UNKNOWN | — | Rejected reason: Red Hat is not the CNA for PHP. CVE was reserved in error; the appropriate CNA should assign CVE IDs for these vulnerabilities. | Aug 24, 2026 |
| CVE-2026-13047 | UNKNOWN | — | Rejected reason: Red Hat is not the CNA for PHP. CVE was reserved in error; the appropriate CNA should assign CVE IDs for these vulnerabilities. | Aug 24, 2026 |
| CVE-2025-26238 | UNKNOWN | — | In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code. | Aug 24, 2026 |
| CVE-2025-26237 | UNKNOWN | — | D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can be exploited to run arbitrary commands. | Aug 24, 2026 |
| CVE-2026-9254 | UNKNOWN | — | An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering … | Aug 24, 2026 |
| CVE-2026-78475 | MEDIUM | 6.1 | A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array … | Aug 24, 2026 |
| CVE-2026-76838 | HIGH | 8.5 | Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule.php resolves the hostname with gethostbyname() and rejects … | Aug 24, 2026 |
| CVE-2026-76837 | MEDIUM | 6.4 | Baserow interpolates a user's display name into the rich-text mention markup without HTML encoding. PATCH /api/user/account/ stores the first_name value verbatim, and the mention renderer … | Aug 24, 2026 |
| CVE-2026-76836 | HIGH | 8.8 | AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is annotated … | Aug 24, 2026 |
| CVE-2026-76835 | CRITICAL | 9.1 | OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the … | Aug 24, 2026 |
| CVE-2026-76073 | HIGH | 8.8 | Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset … | Aug 24, 2026 |
| CVE-2026-76072 | HIGH | 7.4 | The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running unattended. In headless mode and auto mode the … | Aug 24, 2026 |
| CVE-2026-71982 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 24, 2026 |
| CVE-2026-71943 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerability is caused by insufficient filtering of the username and password … | Aug 24, 2026 |
| CVE-2026-71942 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a … | Aug 24, 2026 |
| CVE-2026-71941 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a … | Aug 24, 2026 |
| CVE-2026-71940 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function. The vulnerability is caused by copying the name field into … | Aug 24, 2026 |
| CVE-2026-71939 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. The vulnerability is caused by copying the name field into … | Aug 24, 2026 |
| CVE-2026-71938 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnerability is caused by unsafe copying of the portList field into … | Aug 24, 2026 |
| CVE-2026-71937 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vulnerability is caused by repeated concatenation of the start_date, start_time, duration_time, … | Aug 24, 2026 |
| CVE-2026-71936 | HIGH | 7.2 | Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability is caused by unsafe concatenation of split valueN data into … | Aug 24, 2026 |