Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44750
Total
3597
Critical
13289
High
13145
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-34836 | MEDIUM | 6.5 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and ajax.document.php allows for document access without … | Aug 21, 2026 |
| CVE-2026-34741 | HIGH | 8.6 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbitrary PHP files from … | Aug 21, 2026 |
| CVE-2026-33333 | LOW | 3.5 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the error messages. This issue has … | Aug 21, 2026 |
| CVE-2026-33240 | HIGH | 8.8 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key … | Aug 21, 2026 |
| CVE-2026-33047 | MEDIUM | 4.3 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, an object can be locked by a user who is not assigned … | Aug 21, 2026 |
| CVE-2026-31936 | HIGH | 8.8 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object information through the search operation. This … | Aug 21, 2026 |
| CVE-2026-77811 | HIGH | 8.7 | Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute … | Aug 21, 2026 |
| CVE-2026-77415 | UNKNOWN | — | JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to execute arbitrary code. … | Aug 21, 2026 |
| CVE-2026-77414 | UNKNOWN | — | JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty check. Crafted expressions could … | Aug 21, 2026 |
| CVE-2026-77413 | UNKNOWN | — | JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions … | Aug 21, 2026 |
| CVE-2026-77354 | UNKNOWN | — | kin-openapi is a Go project for handling OpenAPI files. From 0.124.0 until 0.142.0, openapi3filter.sliceMapToSlice in openapi3filter/req_resp_decoder.go converts attacker-controlled sparse indexes from a deepObject query parameter … | Aug 21, 2026 |
| CVE-2026-77220 | MEDIUM | 6.5 | PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a pointer to a stack-local buffer in the document dictionary … | Aug 21, 2026 |
| CVE-2026-77219 | HIGH | 7.1 | GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a … | Aug 21, 2026 |
| CVE-2026-76905 | HIGH | 7.5 | kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openapi3filter/validation_error_encoder.go dereferences e.Parameter.In without checking whether e.Parameter is nil. A … | Aug 21, 2026 |
| CVE-2026-76904 | CRITICAL | 9.8 | GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, … | Aug 21, 2026 |
| CVE-2026-69238 | LOW | 3.5 | There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allows a remote, highly priviliged attacker to insert arbitrary … | Aug 21, 2026 |
| CVE-2026-69237 | LOW | 3.8 | There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker with administrative privileges to insert … | Aug 21, 2026 |
| CVE-2026-69236 | MEDIUM | 6.1 | There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to … | Aug 21, 2026 |
| CVE-2026-69235 | MEDIUM | 6.1 | There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to … | Aug 21, 2026 |
| CVE-2026-69234 | MEDIUM | 6.1 | There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allow a remote, unauthenticated attacker to … | Aug 21, 2026 |
| CVE-2026-69233 | MEDIUM | 5.5 | There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker … | Aug 21, 2026 |
| CVE-2026-69232 | MEDIUM | 5.5 | There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to … | Aug 21, 2026 |
| CVE-2026-69231 | MEDIUM | 5.5 | There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to … | Aug 21, 2026 |
| CVE-2026-69230 | MEDIUM | 5.5 | There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker … | Aug 21, 2026 |
| CVE-2026-69229 | MEDIUM | 5.4 | There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authenticated attacker to insert arbitrary HTML … | Aug 21, 2026 |