Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44750
Total
3597
Critical
13289
High
13145
Medium
CVE ID Severity Score Description Published
CVE-2026-55621 HIGH 7.7 Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing … Aug 21, 2026
CVE-2026-50278 MEDIUM 6.5 iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a `CIccEmbedIO::Read8()` size_t underflow. The … Aug 21, 2026
CVE-2026-48769 CRITICAL 9.9 Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious … Aug 21, 2026
CVE-2026-48756 UNKNOWN Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateCustomVolumeFromBackup` in `internal/server/storage/backend.go` contains an unguarded `*time.Time` dereference on the `ExpiresAt` field … Aug 21, 2026
CVE-2026-48755 CRITICAL 9.9 Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in … Aug 21, 2026
CVE-2026-48754 UNKNOWN Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).createDependentVolumesFromBackup` in `internal/server/storage/backend.go` contains a cluster of unguarded pointer derefs on every … Aug 21, 2026
CVE-2026-48753 CRITICAL 9.9 Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows … Aug 21, 2026
CVE-2026-48752 CRITICAL 9.9 Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read … Aug 21, 2026
CVE-2026-48751 CRITICAL 9.9 Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on … Aug 21, 2026
CVE-2026-48750 CRITICAL 9.9 Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the … Aug 21, 2026
CVE-2026-48749 CRITICAL 9.9 Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary … Aug 21, 2026
CVE-2026-47753 UNKNOWN Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateInstanceFromBackup` in `internal/server/storage/backend.go` contains a nil-pointer dereference that an authenticated user with … Aug 21, 2026
CVE-2026-77806 CRITICAL 9.8 SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection … Aug 21, 2026
CVE-2026-75946 UNKNOWN A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior to 1101.2608.0.0. The vulnerability could potentially allow a local attacker … Aug 21, 2026
CVE-2026-15580 UNKNOWN vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse. This issue affects the PassPortal browser extension: before 3.49.6. Aug 21, 2026
CVE-2026-77780 UNKNOWN Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting … Aug 21, 2026
CVE-2026-77028 UNKNOWN Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66 Aug 21, 2026
CVE-2026-76613 UNKNOWN Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-level user to inject own content … Aug 21, 2026
CVE-2026-76612 UNKNOWN Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user supplied field … Aug 21, 2026
CVE-2026-76611 UNKNOWN Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66. Aug 21, 2026
CVE-2026-75115 UNKNOWN Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Filesystem source's path filter is vulnerable to glob-based pattern … Aug 21, 2026
CVE-2026-59654 UNKNOWN Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality. It affects different modules and plugins of the CloudStack management … Aug 21, 2026
CVE-2026-77776 CRITICAL 9.1 Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat … Aug 21, 2026
CVE-2026-77775 HIGH 8.6 Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that … Aug 21, 2026
CVE-2026-77759 UNKNOWN Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions … Aug 21, 2026