Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44895
Total
3603
Critical
13333
High
13202
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-53548 | CRITICAL | 9.6 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.6.1, the GET /host/db/host/:id/password endpoint in src/backend/database/routes/host.ts accepts … | Aug 19, 2026 |
| CVE-2026-53547 | HIGH | 8.8 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the POST /database/export endpoint creates a user … | Aug 19, 2026 |
| CVE-2026-53546 | CRITICAL | 9.6 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the terminal WebSocket accepts a user-controlled hostConfig.id … | Aug 19, 2026 |
| CVE-2026-53545 | CRITICAL | 9.8 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the DELETE /ssh/tunnel/disconnect/:tunnelName teardown path in src/backend/ssh/tunnel.ts … | Aug 19, 2026 |
| CVE-2026-53542 | HIGH | 8.8 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the archive creation endpoint in src/backend/ssh/file-manager.ts passes … | Aug 19, 2026 |
| CVE-2026-4937 | MEDIUM | 5.3 | IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 could allow a local attacker with administrative privileges to decrypt encrypted data … | Aug 19, 2026 |
| CVE-2026-4936 | MEDIUM | 5.1 | IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 use persistent storage key seeds that … | Aug 19, 2026 |
| CVE-2026-18849 | MEDIUM | 6.8 | IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC … | Aug 19, 2026 |
| CVE-2026-18544 | HIGH | 8.1 | IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image policy enforcement due to improper authorization of pod owner references. | Aug 19, 2026 |
| CVE-2026-18102 | LOW | 3.5 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memory due to an integer underflow during bounds checking. | Aug 19, 2026 |
| CVE-2026-17015 | MEDIUM | 5.4 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to … | Aug 19, 2026 |
| CVE-2026-14978 | MEDIUM | 5.5 | HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads … | Aug 19, 2026 |
| CVE-2026-14514 | MEDIUM | 6.5 | IBM Reliable Scalable Cluster Technology (RSCT) 3.0 could allow a remote attacker to cause a denial of service by sending a specially crafted request due … | Aug 19, 2026 |
| CVE-2026-12634 | MEDIUM | 5.3 | The NVS backend of the Zephyr settings subsystem (subsys/settings/src/settings_nvs.c) reads stored setting-name entries into fixed 74-byte stack buffers and NUL-terminates them with buf[rc] = '\0', … | Aug 19, 2026 |
| CVE-2026-12633 | HIGH | 8.1 | The IPv6 neighbor-discovery code in subsys/net/ip/ipv6_nbr.c processes the 6LoWPAN Context Option (6CO, RFC 6775) carried inside ICMPv6 Router Advertisements. In handle_ra_6co() the 8-bit context_len field … | Aug 19, 2026 |
| CVE-2026-12522 | HIGH | 8.8 | The HL7800 cellular modem driver's +CGCONTRDP: response handler on_cmd_atcmdinfo_ipaddr() in drivers/modem/vendor_standalone/hl7800.c parses the PDP-context dynamic parameters (local address, subnet mask, gateway, and DNS servers) that … | Aug 19, 2026 |
| CVE-2026-11617 | LOW | 3.1 | Tanium addressed a compression bomb vulnerability in Findings. | Aug 19, 2026 |
| CVE-2026-76647 | UNKNOWN | — | Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JSON-RPC dispatcher in app/Domain/Api/Controllers/Jsonrpc.php. The dispatcher does not enforce authorization before invoking … | Aug 19, 2026 |
| CVE-2026-76574 | HIGH | 7.3 | A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the function User::login of the file includes/users/UsersController.php of the component … | Aug 19, 2026 |
| CVE-2026-76572 | MEDIUM | 4.7 | A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element is the function _transformPHP of the file classes/xslt/XSLTransformer.php. The manipulation results in … | Aug 19, 2026 |
| CVE-2026-75593 | UNKNOWN | — | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can … | Aug 19, 2026 |
| CVE-2026-75112 | UNKNOWN | — | A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, … | Aug 19, 2026 |
| CVE-2026-74228 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 19, 2026 |
| CVE-2026-74227 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 19, 2026 |
| CVE-2026-74226 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 19, 2026 |