Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44750
Total
3597
Critical
13289
High
13145
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2021-4475 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 21, 2026 |
| CVE-2019-25725 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 21, 2026 |
| CVE-2019-25715 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 21, 2026 |
| CVE-2017-20232 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 21, 2026 |
| CVE-2026-75933 | HIGH | 7.3 | Jet Admin allows an authenticated attacker to inject JavaScript via the sign-in page's scripts and styles option. Injected script is executed in the context of … | Aug 21, 2026 |
| CVE-2026-75932 | HIGH | 8.6 | Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute … | Aug 21, 2026 |
| CVE-2026-75928 | MEDIUM | 5.3 | The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in requests to users, allowing a remote, unauthenticated attacker to read information about other … | Aug 21, 2026 |
| CVE-2026-69502 | CRITICAL | 10.0 | Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | Aug 21, 2026 |
| CVE-2026-54789 | HIGH | 7.5 | mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to … | Aug 21, 2026 |
| CVE-2026-49114 | HIGH | 7.1 | In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', … | Aug 21, 2026 |
| CVE-2026-22681 | HIGH | 8.5 | OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal network services by submitting arbitrary URLs to the … | Aug 21, 2026 |
| CVE-2025-3127 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 21, 2026 |
| CVE-2025-2795 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 21, 2026 |
| CVE-2026-77815 | HIGH | 7.5 | to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links. A symlink placed inside a scanned … | Aug 21, 2026 |
| CVE-2026-77814 | HIGH | 7.5 | is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent directory with path.startswith(parent_path), without appending a path separator. A directory whose name merely begins … | Aug 21, 2026 |
| CVE-2026-77812 | UNKNOWN | — | DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts to connect to the … | Aug 21, 2026 |
| CVE-2026-77087 | CRITICAL | 9.6 | Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft … | Aug 21, 2026 |
| CVE-2026-75501 | UNKNOWN | — | A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router allows unauthenticated remote attackers to modify NAT port‑forwarding rules via the … | Aug 21, 2026 |
| CVE-2026-63343 | CRITICAL | 9.9 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host … | Aug 21, 2026 |
| CVE-2026-63125 | CRITICAL | 9.9 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and … | Aug 21, 2026 |
| CVE-2026-62941 | CRITICAL | 9.9 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs … | Aug 21, 2026 |
| CVE-2026-62940 | CRITICAL | 9.9 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including … | Aug 21, 2026 |
| CVE-2026-62867 | CRITICAL | 9.9 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument … | Aug 21, 2026 |
| CVE-2026-62313 | MEDIUM | 4.3 | Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricted.containers.privilege=isolated` can be trivially bypassed, allowing a user to … | Aug 21, 2026 |
| CVE-2026-55622 | HIGH | 7.7 | Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the … | Aug 21, 2026 |