Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44895
Total
3603
Critical
13333
High
13202
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-32475 | CRITICAL | 9.0 | Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1. | Aug 19, 2026 |
| CVE-2026-19875 | HIGH | 7.5 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due … | Aug 19, 2026 |
| CVE-2026-19653 | MEDIUM | 6.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to improper handling … | Aug 19, 2026 |
| CVE-2026-19234 | HIGH | 8.2 | Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware boot process image validation path. … | Aug 19, 2026 |
| CVE-2026-18874 | MEDIUM | 6.2 | A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Markup Language) code into the OpenShift Lifecycle Manager … | Aug 19, 2026 |
| CVE-2026-17183 | HIGH | 7.1 | An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side … | Aug 19, 2026 |
| CVE-2025-14603 | UNKNOWN | — | The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentially exposing database contents or causing the … | Aug 19, 2026 |
| CVE-2025-14600 | UNKNOWN | — | An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized administrative access. By manipulating application configuration data, an attacker can force the … | Aug 19, 2026 |
| CVE-2026-75583 | LOW | 3.5 | keeper.sh's calendar module version prior to 2.18.14 contains a server-side request forgery (SSRF) guard bypass vulnerability that allows authenticated attackers to reach private network addresses … | Aug 19, 2026 |
| CVE-2026-75147 | HIGH | 7.1 | FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The keyframe detection loop that searches for a sequence header OBU … | Aug 19, 2026 |
| CVE-2026-75146 | HIGH | 8.1 | FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is … | Aug 19, 2026 |
| CVE-2026-75145 | MEDIUM | 5.8 | FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The OBU size is cast to long before comparison … | Aug 19, 2026 |
| CVE-2026-75144 | HIGH | 7.8 | FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplying … | Aug 19, 2026 |
| CVE-2026-75143 | CRITICAL | 9.8 | FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received … | Aug 19, 2026 |
| CVE-2026-75142 | HIGH | 7.8 | FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack … | Aug 19, 2026 |
| CVE-2026-75141 | HIGH | 7.8 | FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of … | Aug 19, 2026 |
| CVE-2026-72530 | CRITICAL | 9.0 | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and … | Aug 19, 2026 |
| CVE-2026-72529 | CRITICAL | 9.8 | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and … | Aug 19, 2026 |
| CVE-2026-71470 | CRITICAL | 9.1 | A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom Resource (CR) editor, to manipulate Search CR fields such … | Aug 19, 2026 |
| CVE-2026-50173 | UNKNOWN | — | Flow-Like is a platform for building end-to-end use cases. Prior to version 1.0.4, `GET /api/v1/apps/{app_id}/invoke/presign` grants Azure Blob Storage SAS credentials with write and delete … | Aug 19, 2026 |
| CVE-2026-49441 | CRITICAL | 9.1 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.3.0 until 4.14.6 and 5.0.0-beta3, the non-merged branch of … | Aug 19, 2026 |
| CVE-2026-49392 | MEDIUM | 5.3 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in … | Aug 19, 2026 |
| CVE-2026-48162 | CRITICAL | 9.1 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, DistributedAPI.send_tmp_file() in framework/wazuh/core/cluster/dapi/dapi.py joins … | Aug 19, 2026 |
| CVE-2026-48024 | CRITICAL | 9.1 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, cluster.unmerge_info() in framework/wazuh/core/cluster/cluster.py constructs … | Aug 19, 2026 |
| CVE-2026-45798 | HIGH | 7.5 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies … | Aug 19, 2026 |