Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44895
Total
3603
Critical
13333
High
13202
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-55519 | MEDIUM | 5.4 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permission can delete files attached to assets outside … | Aug 19, 2026 |
| CVE-2026-55483 | UNKNOWN | — | Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.create permission can submit the admin permission while creating a user … | Aug 19, 2026 |
| CVE-2026-55482 | MEDIUM | 6.3 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/BulkAssetsController.php update() to submit company_id directly without Company::getIdForCurrentUser(), allowing assets to … | Aug 19, 2026 |
| CVE-2026-50550 | MEDIUM | 5.8 | Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users can reset a superadmin's two-factor authentication through app/Http/Controllers/Api/UsersController.php … | Aug 19, 2026 |
| CVE-2026-49976 | MEDIUM | 6.5 | Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update mode to overwrite the email … | Aug 19, 2026 |
| CVE-2026-49870 | MEDIUM | 5.9 | Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or attempt counter, allowing an attacker with valid … | Aug 19, 2026 |
| CVE-2026-19321 | MEDIUM | 6.7 | Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware. An attacker with service access … | Aug 19, 2026 |
| CVE-2026-19198 | UNKNOWN | — | Akaunting 3.1.21 contains an authenticated improper authorization vulnerability in the common BulkActions dispatcher.This issue affects Akaunting: 3.1.21. | Aug 19, 2026 |
| CVE-2026-18848 | HIGH | 8.3 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. … | Aug 19, 2026 |
| CVE-2026-18681 | MEDIUM | 6.8 | IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP firmware update process. … | Aug 19, 2026 |
| CVE-2026-18315 | CRITICAL | 9.8 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all … | Aug 19, 2026 |
| CVE-2026-17494 | HIGH | 8.2 | IBM Power Systems Firmware FW1120.00, and FW1110.00 through FW1110.30 is affected by a vulnerability in the interface between the BMC and the host system. An … | Aug 19, 2026 |
| CVE-2026-17429 | HIGH | 8.1 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is … | Aug 19, 2026 |
| CVE-2026-17100 | HIGH | 8.2 | Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1, and OP940.00 - OP940.81 is affected by a vulnerability … | Aug 19, 2026 |
| CVE-2026-17093 | HIGH | 8.2 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, FW950.00 through FW950.H2, OP940.00 through OP940.a1 (Power9), and OP940.00 - OP940.81 (Power HMC) is … | Aug 19, 2026 |
| CVE-2026-16938 | MEDIUM | 6.9 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in access controls over privileged … | Aug 19, 2026 |
| CVE-2026-16930 | HIGH | 8.2 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the interface between the BMC/FSP and the … | Aug 19, 2026 |
| CVE-2026-16835 | CRITICAL | 9.6 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network … | Aug 19, 2026 |
| CVE-2026-16832 | HIGH | 8.4 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network … | Aug 19, 2026 |
| CVE-2026-16828 | HIGH | 7.6 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. … | Aug 19, 2026 |
| CVE-2026-16687 | CRITICAL | 9.6 | IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. … | Aug 19, 2026 |
| CVE-2026-75149 | HIGH | 8.8 | marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP … | Aug 19, 2026 |
| CVE-2026-73829 | UNKNOWN | — | Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote client to redeem one confirmed on-chain payment for multiple paid-resource accesses. The type="hash" … | Aug 19, 2026 |
| CVE-2026-73541 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet through concurrent sponsored payments, denying … | Aug 19, 2026 |
| CVE-2026-73136 | UNKNOWN | — | Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated third party to obtain paid resources by replaying a transfer settled by an unrelated payer. … | Aug 19, 2026 |