Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44710
Total
3597
Critical
13280
High
13130
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-19685 | HIGH | 7.1 | NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user … | Aug 24, 2026 |
| CVE-2026-18349 | UNKNOWN | — | Improper protection against voltage and clock glitches vulnerability in Microchip SAMA5D4 allows Hardware Fault Injection. This issue affects SAMA5D4. | Aug 24, 2026 |
| CVE-2026-15469 | UNKNOWN | — | The use of hard-coded cryptographic key vulnerability has been identified in the mesh functionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6. A shared … | Aug 24, 2026 |
| CVE-2025-36940 | HIGH | 8.8 | Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from Userspace to Kernel (AP) | Aug 24, 2026 |
| CVE-2025-36939 | UNKNOWN | — | Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a … | Aug 24, 2026 |
| CVE-2026-78416 | UNKNOWN | — | Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. … | Aug 24, 2026 |
| CVE-2026-76071 | CRITICAL | 9.8 | Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized … | Aug 24, 2026 |
| CVE-2026-76070 | CRITICAL | 9.8 | Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized … | Aug 24, 2026 |
| CVE-2026-71366 | HIGH | 7.7 | A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs … | Aug 24, 2026 |
| CVE-2026-71364 | HIGH | 7.2 | A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts zip and tar archive members by joining the project … | Aug 24, 2026 |
| CVE-2026-67204 | MEDIUM | 5.4 | BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by … | Aug 24, 2026 |
| CVE-2026-21752 | HIGH | 7.5 | HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or compromise of the system by exploiting … | Aug 24, 2026 |
| CVE-2026-13343 | MEDIUM | 5.3 | The UMP Stream responder library in lib/midi2/ump_stream_responder.c builds reply packets in a 16-byte struct midi_ump (uint32_t data[4]). The builders make_endpoint_info() and make_function_block_info() populate only the … | Aug 24, 2026 |
| CVE-2026-13212 | HIGH | 8.8 | The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device writes into the used ring. In virtio_isr() (drivers/virtio/virtio_common.c), the device-written … | Aug 24, 2026 |
| CVE-2026-12556 | UNKNOWN | — | Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. … | Aug 24, 2026 |
| CVE-2026-12555 | UNKNOWN | — | Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. … | Aug 24, 2026 |
| CVE-2026-12554 | UNKNOWN | — | Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. … | Aug 24, 2026 |
| CVE-2025-68825 | HIGH | 7.5 | HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, container breakout, and interception of sensitive internal communications. | Aug 24, 2026 |
| CVE-2026-9728 | MEDIUM | 6.4 | The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out of live userspace memory, and then forwarded the … | Aug 24, 2026 |
| CVE-2026-78414 | HIGH | 8.0 | Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux, Windows and MacOS allows an adjacent-network attacker … | Aug 24, 2026 |
| CVE-2026-78391 | UNKNOWN | — | RansomLook contains a stored cross-site scripting (XSS) vulnerability in the cryptocurrency wallet detail view. Cryptocurrency addresses and blockchain names originating from external sources, including the … | Aug 24, 2026 |
| CVE-2026-78387 | UNKNOWN | — | RansomLook contains an authorization weakness in the web-based configuration editor exposed through the /admin/config endpoint. The endpoint requires an authenticated session but does not perform … | Aug 24, 2026 |
| CVE-2026-76055 | UNKNOWN | — | Improper Neutralization of Special Elements used in an OS Command in the package manager component of Black Duck blackduck-c-cpp before 3.0.7 allows an actor able … | Aug 24, 2026 |
| CVE-2026-76054 | UNKNOWN | — | Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute code within the scanned project's … | Aug 24, 2026 |
| CVE-2026-65053 | MEDIUM | 6.1 | Horde IMP's AppleDouble MIME viewer writes an attacker-controlled attachment name into an HTML status block without escaping it. In lib/Mime/Viewer/Appledouble.php, _IMPrender() obtains the name of … | Aug 24, 2026 |