Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44895
Total
3603
Critical
13333
High
13202
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-76582 | HIGH | 7.4 | A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected is the function popen/system of the file /cgi-bin/ping.cgi of the component ssi. Executing a manipulation of … | Aug 19, 2026 |
| CVE-2026-76576 | MEDIUM | 4.3 | A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. This impacts the function fileDownload/resourceDownload of the file ruoyi-admin/src/main/java/com/ruoyi/web/controller/common/CommonController.java of the component Common Download Endpoint. … | Aug 19, 2026 |
| CVE-2026-76139 | HIGH | 8.0 | A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity … | Aug 19, 2026 |
| CVE-2026-75616 | UNKNOWN | — | An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations. An authenticated administrator … | Aug 19, 2026 |
| CVE-2026-75596 | UNKNOWN | — | Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/main/java/io/netty/handler/ssl/SslClientHelloHandler.java … | Aug 19, 2026 |
| CVE-2026-75595 | UNKNOWN | — | Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, … | Aug 19, 2026 |
| CVE-2026-75569 | HIGH | 7.7 | A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning … | Aug 19, 2026 |
| CVE-2026-75476 | LOW | 3.1 | Tanium addressed a compression bomb vulnerability in Threat Response. | Aug 19, 2026 |
| CVE-2026-69222 | HIGH | 7.5 | LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.2, the join filter in src/filters/array.ts computes complexity from array.length … | Aug 19, 2026 |
| CVE-2026-68555 | MEDIUM | 6.5 | Coturn is a free open source implementation of TURN and STUN Server. In 4.15.0, an authenticated TURN user can repeatedly resume one allocation from fresh … | Aug 19, 2026 |
| CVE-2026-68554 | UNKNOWN | — | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an on-path attacker can append attributes after MESSAGE-INTEGRITY to an … | Aug 19, 2026 |
| CVE-2026-68553 | HIGH | 7.1 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can place printf-style format specifiers in … | Aug 19, 2026 |
| CVE-2026-68552 | MEDIUM | 5.3 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an unauthenticated remote client can send a STUN message over … | Aug 19, 2026 |
| CVE-2026-62727 | HIGH | 7.0 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | Aug 19, 2026 |
| CVE-2026-61556 | UNKNOWN | — | LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. From 10.26.0 until 10.27.1, the strip_html filter in src/filters/html.ts can enter an … | Aug 19, 2026 |
| CVE-2026-54743 | UNKNOWN | — | Lemmy is a link aggregator and forum for the fediverse. Prior to lemmy-ui 0.19.19-beta.1, LemmyNet/lemmy-ui renders Markdown in src/shared/markdown.ts for post bodies, comment bodies, private … | Aug 19, 2026 |
| CVE-2026-54741 | UNKNOWN | — | Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, Lemmy blocks new private messages from a sender after the … | Aug 19, 2026 |
| CVE-2026-54740 | MEDIUM | 6.5 | Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, a lower-ranked remote moderator can remove a higher-ranked moderator by … | Aug 19, 2026 |
| CVE-2026-54739 | UNKNOWN | — | Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, Lemmy's login endpoint in crates/api/api/src/local_user/login.rs returns different errors depending on … | Aug 19, 2026 |
| CVE-2026-54738 | MEDIUM | 6.5 | Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, actix-web ConnectionInfo::realip_remote_addr reads the first value of X-Forwarded-For as the … | Aug 19, 2026 |
| CVE-2026-54494 | UNKNOWN | — | Koel is a free, open-source music streaming solution. Prior to 9.7.1, App\Helpers\Network::isPublicHost() uses filter_var() with FILTER_FLAG_NO_PRIV_RANGE and FILTER_FLAG_NO_RES_RANGE, which treats NAT64 64:ff9b::/96 and 6to4 2002::/16 … | Aug 19, 2026 |
| CVE-2026-54493 | HIGH | 7.7 | Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createInternetRadioStation.view and updateInternetRadioStation.view routes accept an authenticated user's streamUrl without the SafeUrl … | Aug 19, 2026 |
| CVE-2026-54492 | MEDIUM | 4.3 | Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createPodcastChannel.view route accepts an authenticated user's private URL because app/Http/Requests/Subsonic/CreatePodcastChannelRequest.php does not … | Aug 19, 2026 |
| CVE-2026-54491 | HIGH | 7.1 | Koel is a free, open-source music streaming solution. Prior to 9.7.1, outbound podcast and radio fetch paths perform a point-in-time App\Helpers\Network::isPublicHost() or isSafeUrl() check without … | Aug 19, 2026 |
| CVE-2026-53549 | HIGH | 7.7 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the POST /host/db/proxy/test endpoint accepts the singleProxy, … | Aug 19, 2026 |