Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44895
Total
3603
Critical
13333
High
13202
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-44901 | HIGH | 8.4 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AffectedItemsWazuhResult.merge() in framework/wazuh/core/results.py trusts … | Aug 19, 2026 |
| CVE-2026-44256 | MEDIUM | 5.3 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.4.0 until 4.14.6 and 5.0.0-beta2, api/api/middlewares.py decodes the Basic … | Aug 19, 2026 |
| CVE-2026-44255 | MEDIUM | 5.3 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AuthenticationManager.check_user() in framework/wazuh/rbac/orm.py performs … | Aug 19, 2026 |
| CVE-2026-41424 | HIGH | 8.2 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.9.0 until 4.10.4 and 4.14.6, PUT /security/users/{user_id} in api/api/controllers/security_controller.py … | Aug 19, 2026 |
| CVE-2026-20359 | CRITICAL | 9.9 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This … | Aug 19, 2026 |
| CVE-2026-20358 | CRITICAL | 10.0 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This … | Aug 19, 2026 |
| CVE-2026-20357 | CRITICAL | 10.0 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This … | Aug 19, 2026 |
| CVE-2026-20327 | MEDIUM | 6.5 | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack … | Aug 19, 2026 |
| CVE-2026-20320 | HIGH | 7.5 | A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on … | Aug 19, 2026 |
| CVE-2026-20319 | HIGH | 7.5 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. … | Aug 19, 2026 |
| CVE-2026-20318 | CRITICAL | 9.6 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. … | Aug 19, 2026 |
| CVE-2026-20317 | CRITICAL | 10.0 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. … | Aug 19, 2026 |
| CVE-2026-20315 | CRITICAL | 10.0 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. … | Aug 19, 2026 |
| CVE-2026-20314 | MEDIUM | 5.0 | A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to … | Aug 19, 2026 |
| CVE-2026-20302 | MEDIUM | 6.1 | A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected … | Aug 19, 2026 |
| CVE-2026-20232 | MEDIUM | 5.4 | A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an authenticated, remote attacker to conduct a stored … | Aug 19, 2026 |
| CVE-2026-20231 | CRITICAL | 9.9 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. … | Aug 19, 2026 |
| CVE-2026-20177 | MEDIUM | 5.3 | A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an unauthenticated, remote attacker to cause the … | Aug 19, 2026 |
| CVE-2026-20030 | CRITICAL | 10.0 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This … | Aug 19, 2026 |
| CVE-2024-13942 | HIGH | 7.6 | Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of booting from external media (SPI NOR or NAND, EMMC … | Aug 19, 2026 |
| CVE-2026-64852 | UNKNOWN | — | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.8, the Grav API … | Aug 19, 2026 |
| CVE-2026-64851 | UNKNOWN | — | Grav Shortcode Core Plugin allows for the development shortcode plugins that utilize the common format utilized by WordPress and BBCode. Prior to 6.2.2, Grav Shortcode … | Aug 19, 2026 |
| CVE-2026-64850 | UNKNOWN | — | Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/Common/Data/Blueprint.php sends an editor-controlled Class::method provider and arguments to call_user_func_array() without rejecting dangerous … | Aug 19, 2026 |
| CVE-2026-63408 | HIGH | 7.5 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16, the Grav API … | Aug 19, 2026 |
| CVE-2026-63407 | HIGH | 8.2 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16, the Grav API … | Aug 19, 2026 |