Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44710
Total
3597
Critical
13280
High
13130
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-71910 | HIGH | 7.2 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability is caused by insufficient validation of the CMD0, CMD3, and … | Aug 24, 2026 |
| CVE-2026-71909 | HIGH | 7.2 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is caused by insufficient filtering of the time field before … | Aug 24, 2026 |
| CVE-2026-71908 | HIGH | 7.2 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vulnerability is caused by insufficient sanitization of the meshdevice_index and meshdevice_ip … | Aug 24, 2026 |
| CVE-2026-71907 | HIGH | 7.2 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability is caused by insufficient filtering of the selectSlaves field before … | Aug 24, 2026 |
| CVE-2026-71906 | HIGH | 7.2 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is caused by insufficient validation of the lanIp and lanNetmask … | Aug 24, 2026 |
| CVE-2026-71905 | MEDIUM | 6.5 | Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying absolute filesystem paths to the GET … | Aug 24, 2026 |
| CVE-2026-71904 | HIGH | 7.2 | Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerability is caused by insufficient filtering of dangerous characters before the … | Aug 24, 2026 |
| CVE-2026-34491 | UNKNOWN | — | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls Metasys 14 and Johnson Controls Metasys 15 allows Cross Site Scripting. … | Aug 24, 2026 |
| CVE-2026-16348 | UNKNOWN | — | An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by … | Aug 24, 2026 |
| CVE-2026-13213 | MEDIUM | 5.3 | The Hearing Access Service (HAS) GATT server in subsys/bluetooth/audio/has.c installs a connection-callback set unconditionally via BT_CONN_CB_DEFINE, so security_changed() runs for every connection that establishes security … | Aug 24, 2026 |
| CVE-2026-78465 | HIGH | 7.0 | A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation … | Aug 24, 2026 |
| CVE-2026-78329 | UNKNOWN | — | Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.11.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before … | Aug 24, 2026 |
| CVE-2026-77915 | CRITICAL | 9.8 | rConfig Core 8.0.0 before 8.2.13 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate … | Aug 24, 2026 |
| CVE-2026-77914 | MEDIUM | 6.5 | rConfig Core 8.0.0 before 8.2.13 contains a path traversal vulnerability that allows authenticated users to read arbitrary files by supplying crafted filenames containing directory traversal … | Aug 24, 2026 |
| CVE-2026-76831 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 24, 2026 |
| CVE-2026-76830 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 24, 2026 |
| CVE-2026-76829 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 24, 2026 |
| CVE-2026-75099 | MEDIUM | 5.3 | Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through 1.19.1. Users are recommended to upgrade to version 1.20.0, … | Aug 24, 2026 |
| CVE-2026-71300 | UNKNOWN | — | Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 … | Aug 24, 2026 |
| CVE-2026-66908 | UNKNOWN | — | Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.22.0. The camel-main embedded HTTP server can … | Aug 24, 2026 |
| CVE-2026-66907 | UNKNOWN | — | Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 … | Aug 24, 2026 |
| CVE-2026-66906 | UNKNOWN | — | Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from … | Aug 24, 2026 |
| CVE-2026-63621 | UNKNOWN | — | Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Knative component The Knative consumer … | Aug 24, 2026 |
| CVE-2026-60093 | UNKNOWN | — | Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 … | Aug 24, 2026 |
| CVE-2026-59230 | UNKNOWN | — | Improper input validation vulnerability in Apache Camel. This issue affects Apache Camel: from 2.17.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The … | Aug 24, 2026 |