Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44839
Total
3598
Critical
13323
High
13186
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-70651 | UNKNOWN | — | libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick support can … | Aug 20, 2026 |
| CVE-2026-69242 | UNKNOWN | — | libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoadTiff can evade scanline … | Aug 20, 2026 |
| CVE-2026-68921 | MEDIUM | 4.7 | DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpolates the rotate option into an SVG transform attribute without XML escaping … | Aug 20, 2026 |
| CVE-2026-67567 | CRITICAL | 9.9 | A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass … | Aug 20, 2026 |
| CVE-2026-67446 | MEDIUM | 5.3 | Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-supplied image attachments into a full raster before checking decoded … | Aug 20, 2026 |
| CVE-2026-67445 | MEDIUM | 5.3 | Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP commands through internal/smtpd/smtpd.go session.readLine() using bufio.Reader.ReadString before session.parseLine() parses … | Aug 20, 2026 |
| CVE-2026-53804 | HIGH | 7.2 | OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying … | Aug 20, 2026 |
| CVE-2026-52021 | UNKNOWN | — | An issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30) allows a remote attacker to obtain sensitive information via the src/middleware.ts, and src/app/api/mobile/search/route.ts components. | Aug 20, 2026 |
| CVE-2026-43798 | UNKNOWN | — | A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any application built on swift-nio-ssh. … | Aug 20, 2026 |
| CVE-2026-19755 | UNKNOWN | — | NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled command and NSBundlePath values.This issue affects NoSleep: 1.5.1. | Aug 20, 2026 |
| CVE-2026-18420 | HIGH | 8.8 | Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the … | Aug 20, 2026 |
| CVE-2026-77151 | LOW | 3.7 | A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affected by this issue is the function MD5Encrypt of the file internal/util/crypto/crypto.go. Performing … | Aug 20, 2026 |
| CVE-2026-75910 | MEDIUM | 6.5 | Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an authenticated remote user to read … | Aug 20, 2026 |
| CVE-2026-72861 | MEDIUM | 5.8 | The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition. verifyWebhook in node/github-issue-bot/src/github.js and in node-typescript/github-issue-bot/src/github.ts returns "typeof signature !== 'string' … | Aug 20, 2026 |
| CVE-2026-63723 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 20, 2026 |
| CVE-2026-9033 | UNKNOWN | — | An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of … | Aug 20, 2026 |
| CVE-2026-8717 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 20, 2026 |
| CVE-2026-77148 | CRITICAL | 9.9 | A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET§ion=ptest_channel of the component Web Management. The manipulation results … | Aug 20, 2026 |
| CVE-2026-75526 | MEDIUM | 4.4 | django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. From 5.0.8 until 5.0.9, ContentRenderer.render_placeholder in cms/plugin_rendering.py can pass stored, attacker-controlled … | Aug 20, 2026 |
| CVE-2026-75514 | MEDIUM | 5.9 | BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklist, greylist, and antibot modules in src/common/core/blacklist/blacklist.lua, src/common/core/greylist/greylist.lua, and src/common/core/antibot/antibot.lua trust PTR suffix … | Aug 20, 2026 |
| CVE-2026-72854 | MEDIUM | 5.3 | msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_buffer API, computes its new buffer size using an unchecked size_t addition of the requested size and the … | Aug 20, 2026 |
| CVE-2026-72852 | HIGH | 7.8 | hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken from a .cfg file in unchecked 32-bit int arithmetic. In … | Aug 20, 2026 |
| CVE-2026-6822 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 20, 2026 |
| CVE-2026-6260 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 20, 2026 |
| CVE-2026-66788 | CRITICAL | 9.9 | A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection … | Aug 20, 2026 |