Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44839
Total
3598
Critical
13323
High
13186
Medium
CVE ID Severity Score Description Published
CVE-2026-43678 MEDIUM 5.3 An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping … Aug 20, 2026
CVE-2026-19683 UNKNOWN A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over … Aug 20, 2026
CVE-2026-19586 UNKNOWN A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied … Aug 20, 2026
CVE-2026-15743 UNKNOWN Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable. The _serve_static method always sets the Cache-Control header to "public", with no means of … Aug 20, 2026
CVE-2026-77036 MEDIUM 6.3 A vulnerability was found in elunez eladmin up to 2.7. The impacted element is the function EmailController/AliPayController/GeneratorController/GenConfigController. The manipulation results in improper authorization. The attack … Aug 20, 2026
CVE-2026-77031 HIGH 7.4 A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreateFileName of the file /goform/formcreateFileName. The manipulation of the argument … Aug 20, 2026
CVE-2026-76641 HIGH 7.5 Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. … Aug 20, 2026
CVE-2026-73259 MEDIUM 5.4 Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment … Aug 20, 2026
CVE-2026-73258 MEDIUM 6.5 Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in … Aug 20, 2026
CVE-2026-73257 CRITICAL 9.1 Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length … Aug 20, 2026
CVE-2026-73256 CRITICAL 9.1 Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a … Aug 20, 2026
CVE-2026-73255 MEDIUM 6.5 Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control an SSI-enabled file can place directory traversal sequences … Aug 20, 2026
CVE-2026-73254 MEDIUM 5.4 Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its … Aug 20, 2026
CVE-2026-73253 UNKNOWN Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain … Aug 20, 2026
CVE-2026-73251 UNKNOWN Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured … Aug 20, 2026
CVE-2026-72847 MEDIUM 4.6 broot renders each file and directory name in its interactive tree view exactly as read from the filesystem. Names are converted with a plain to_string_lossy() … Aug 20, 2026
CVE-2026-72844 MEDIUM 6.3 The Lean 4 kernel does not verify that the structure named in a projection expression matches the type of the value being projected, and environment::add_inductive … Aug 20, 2026
CVE-2026-63495 HIGH 7.5 Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frames in evws->incomplete_frames without enforcing a total … Aug 20, 2026
CVE-2026-63388 HIGH 8.4 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when bufferevent_socket_set_conn_address_ copies a kernel-supplied AF_UNIX … Aug 20, 2026
CVE-2026-63387 HIGH 7.0 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_to_labels formats a name-bearing … Aug 20, 2026
CVE-2026-63385 UNKNOWN Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into … Aug 20, 2026
CVE-2026-63384 UNKNOWN Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evtag_unmarshal_header uses evtag_decode_int to decode … Aug 20, 2026
CVE-2026-63383 UNKNOWN Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c when decode_tag_internal requests at … Aug 20, 2026
CVE-2026-63382 UNKNOWN Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Transfer-Encoding headers, comma-separated Transfer-Encoding values, … Aug 20, 2026
CVE-2026-63381 UNKNOWN Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len … Aug 20, 2026