Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44793
Total
3597
Critical
13314
High
13164
Medium
CVE ID Severity Score Description Published
CVE-2026-55489 MEDIUM 4.9 BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could submit a presentationId through /api/graphql that identified a presentation belonging to another meeting. … Aug 20, 2026
CVE-2026-55015 MEDIUM 5.5 Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally. Aug 20, 2026
CVE-2026-55013 HIGH 7.1 Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally. Aug 20, 2026
CVE-2026-54509 MEDIUM 6.5 TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src/routes/journey.ts returns the result of getJourneyShareLink() from server/src/services/journeyShareService.ts without checking … Aug 20, 2026
CVE-2026-54508 UNKNOWN TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before native redirect following in importGoogleList() and importNaverList() in server/src/services/placeService.ts … Aug 20, 2026
CVE-2026-54505 UNKNOWN TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK interpolates the unescaped activeSuggestion.title value into journey.frontpage.suggestionText through client/src/i18n/TranslationContext.tsx … Aug 20, 2026
CVE-2026-54389 MEDIUM 5.5 Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser that allows attackers to terminate the Ghidra process by supplying a crafted … Aug 20, 2026
CVE-2026-50192 UNKNOWN Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub credentials in … Aug 20, 2026
CVE-2026-49436 HIGH 7.3 LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URLs without any format … Aug 20, 2026
CVE-2026-49245 LOW 3.7 SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads … Aug 20, 2026
CVE-2026-49244 MEDIUM 5.9 SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP download endpoint for a browsable share validates … Aug 20, 2026
CVE-2026-49217 HIGH 7.5 Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API … Aug 20, 2026
CVE-2026-46682 HIGH 8.5 BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingId and userId values used by refreshBreakoutRoomsVisibleForUsers … Aug 20, 2026
CVE-2026-46355 HIGH 7.1 BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinExistingUser through bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy. A requester able to supply an existingUserID for an active participant … Aug 20, 2026
CVE-2026-19783 MEDIUM 6.7 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A … Aug 20, 2026
CVE-2026-19449 HIGH 8.8 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local user to executes the … Aug 20, 2026
CVE-2026-19448 MEDIUM 6.5 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful exploitation … Aug 20, 2026
CVE-2026-19446 HIGH 7.5 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC … Aug 20, 2026
CVE-2026-19442 HIGH 8.2 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful … Aug 20, 2026
CVE-2026-19437 HIGH 8.1 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow. Aug 20, 2026
CVE-2026-18842 HIGH 8.4 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to an out-of-bounds write. Aug 20, 2026
CVE-2026-18840 HIGH 8.2 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improper validation of an … Aug 20, 2026
CVE-2026-18835 CRITICAL 9.9 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of … Aug 20, 2026
CVE-2026-18832 HIGH 8.8 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow. Aug 20, 2026
CVE-2026-18828 MEDIUM 5.4 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack-based … Aug 20, 2026