Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44750
Total
3597
Critical
13289
High
13145
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-53525 | HIGH | 7.4 | WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions … | Aug 21, 2026 |
| CVE-2026-53524 | MEDIUM | 6.5 | WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay module's WebSocket permessage-deflate decompression function relay_websocket_inflate() … | Aug 21, 2026 |
| CVE-2026-53499 | UNKNOWN | — | FORT Validator is a Resource Public Key Infrastructure (RPKI) relying-party validator that produces validated route-origin data. FORT Validator versions through 1.6.7 contain an origin-validation error … | Aug 21, 2026 |
| CVE-2026-49360 | UNKNOWN | — | Recce is a data-validation toolkit for enhanced dbt (data build tool) PR review. Prior to version 1.50.0, OSS server deployments that expose the server to … | Aug 21, 2026 |
| CVE-2026-48106 | UNKNOWN | — | Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's cluster replication receiver at `internal/cluster/replication/receiver.go` validates only the wire-format envelope … | Aug 21, 2026 |
| CVE-2026-48105 | UNKNOWN | — | Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's Raft FSM (`internal/cluster/raft/fsm.go:applyRegisterFile`) accepts attacker-chosen file paths in manifest-registration proposals … | Aug 21, 2026 |
| CVE-2026-48050 | UNKNOWN | — | Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof` handlers at `/debug/pprof/*` via `app.Use(pprof.New())` in `internal/api/server.go`, and `/debug/pprof` … | Aug 21, 2026 |
| CVE-2026-47735 | UNKNOWN | — | Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc's user-SQL validator (`internal/api/query.go:ValidateSQLRequest`) blocked only `read_parquet(` and `arc_partition_agg(` via regex denylist. … | Aug 21, 2026 |
| CVE-2026-34949 | MEDIUM | 6.5 | Combodo iTop is a web based IT service management tool.Prior to 3.2.3, an unauthenticated user could delete the .readonly file on iTop instances — a … | Aug 21, 2026 |
| CVE-2026-34948 | HIGH | 7.7 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in the SELECT clause are protected by the silos … | Aug 21, 2026 |
| CVE-2026-11805 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 21, 2026 |
| CVE-2026-11615 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 21, 2026 |
| CVE-2026-11609 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 21, 2026 |
| CVE-2026-11418 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 21, 2026 |
| CVE-2026-53531 | UNKNOWN | — | RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, RaTeX’s recursive-descent parser recurses one (or more) native stack frame per … | Aug 21, 2026 |
| CVE-2026-53530 | UNKNOWN | — | RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, the public parser entrypoint `ratex_parser::parse(&str)` panics on the 9-byte input `\verbéxé` … | Aug 21, 2026 |
| CVE-2026-53529 | UNKNOWN | — | LeafWiki is a self-hosted wiki. Prior to version 0.10.2, page titles returned by the search API could be rendered as raw HTML in the frontend. … | Aug 21, 2026 |
| CVE-2026-53528 | HIGH | 8.8 | LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset rename functionality. An authenticated user with editor permissions … | Aug 21, 2026 |
| CVE-2026-53527 | HIGH | 8.8 | LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user update API. An authenticated user could update their … | Aug 21, 2026 |
| CVE-2026-53509 | MEDIUM | 5.7 | CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a … | Aug 21, 2026 |
| CVE-2026-53497 | MEDIUM | 5.3 | CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without authentication and returns the other_sessions array, which exposes metadata of … | Aug 21, 2026 |
| CVE-2026-53487 | MEDIUM | 4.3 | Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated Kite users with any role can request `/api/v1/overview` for a cluster that their roles do … | Aug 21, 2026 |
| CVE-2026-53468 | MEDIUM | 4.6 | Typemill is a flat-file, Markdown-based content management system designed for informational documentation websites. Versions prior to 2.23.0 are vulnerable to stored HTML attribute injection in … | Aug 21, 2026 |
| CVE-2026-49849 | CRITICAL | 9.1 | xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administrator to upload executable files … | Aug 21, 2026 |
| CVE-2026-43980 | MEDIUM | 6.3 | Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc76095083552135, code names (long_name, short_name) received via MQTT are stored … | Aug 21, 2026 |