Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44793
Total
3597
Critical
13314
High
13164
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-76156 | UNKNOWN | — | OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system … | Aug 21, 2026 |
| CVE-2026-76155 | UNKNOWN | — | Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the management platform … | Aug 21, 2026 |
| CVE-2026-77651 | CRITICAL | 9.8 | The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue … | Aug 21, 2026 |
| CVE-2026-77650 | CRITICAL | 9.8 | The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue … | Aug 21, 2026 |
| CVE-2026-77649 | CRITICAL | 9.8 | The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue … | Aug 21, 2026 |
| CVE-2026-43679 | LOW | 2.4 | This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch … | Aug 21, 2026 |
| CVE-2026-20679 | MEDIUM | 4.3 | The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. Processing a maliciously crafted … | Aug 21, 2026 |
| CVE-2026-16520 | UNKNOWN | — | Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, and Genians Genian ZTNA … | Aug 21, 2026 |
| CVE-2026-77648 | LOW | 2.2 | In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service … | Aug 20, 2026 |
| CVE-2026-77647 | CRITICAL | 9.8 | SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification … | Aug 20, 2026 |
| CVE-2026-77113 | UNKNOWN | — | Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the … | Aug 20, 2026 |
| CVE-2026-77646 | UNKNOWN | — | A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of … | Aug 20, 2026 |
| CVE-2026-77645 | UNKNOWN | — | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of … | Aug 20, 2026 |
| CVE-2026-77644 | UNKNOWN | — | A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition. | Aug 20, 2026 |
| CVE-2026-77643 | MEDIUM | 4.4 | A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue … | Aug 20, 2026 |
| CVE-2026-77642 | HIGH | 7.5 | tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for … | Aug 20, 2026 |
| CVE-2026-72860 | HIGH | 8.5 | The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That … | Aug 20, 2026 |
| CVE-2026-72858 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 20, 2026 |
| CVE-2026-72848 | HIGH | 8.6 | SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over … | Aug 20, 2026 |
| CVE-2026-72846 | MEDIUM | 6.4 | Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/clients/MicrosoftTeams/MicrosoftTeamsClient.ts. In affected versions … | Aug 20, 2026 |
| CVE-2026-72843 | CRITICAL | 9.8 | The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the … | Aug 20, 2026 |
| CVE-2026-72818 | HIGH | 7.5 | The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisting … | Aug 20, 2026 |
| CVE-2026-70105 | MEDIUM | 6.5 | Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | Aug 20, 2026 |
| CVE-2026-69855 | HIGH | 7.7 | Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network. | Aug 20, 2026 |
| CVE-2026-69851 | CRITICAL | 9.9 | Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | Aug 20, 2026 |