Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45002
Total
3609
Critical
13358
High
13243
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-53451 | CRITICAL | 9.8 | Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command … | Aug 19, 2026 |
| CVE-2026-52889 | CRITICAL | 9.8 | Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer … | Aug 19, 2026 |
| CVE-2026-52834 | HIGH | 7.3 | jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a crafted JPEG XL image on a 32-bit platform … | Aug 19, 2026 |
| CVE-2026-52792 | UNKNOWN | — | Algernon is a small self-contained pure-Go web server. Prior to 1.17.9, Algernon on Windows selects a file handler in engine/handlers.go by calling filepath.Ext() without first … | Aug 19, 2026 |
| CVE-2026-50149 | MEDIUM | 6.5 | Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, when an `HTTPProxy` is configured with incompatible combination of both `.spec.virtualhost.tls.enableFallbackCertificate: … | Aug 19, 2026 |
| CVE-2026-49817 | HIGH | 7.8 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit … | Aug 19, 2026 |
| CVE-2026-49816 | HIGH | 7.8 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit … | Aug 19, 2026 |
| CVE-2026-49289 | HIGH | 7.5 | The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20.2, the library permits attacker-controlled XPath transforms while processing XML … | Aug 19, 2026 |
| CVE-2026-49283 | HIGH | 8.7 | The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1, the HTTPArtifact::receive() flow can treat … | Aug 19, 2026 |
| CVE-2026-49255 | HIGH | 8.8 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm constructs operating system commands in src/app/lib/fs.js by interpolating untrusted file paths into the rmrf(), mv(), … | Aug 19, 2026 |
| CVE-2026-49253 | HIGH | 7.1 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm uses remote-supplied filenames directly with path.join() while receiving Zmodem and Trzsz transfers. In src/app/server/zmodem.js, prepareReceiveFile() … | Aug 19, 2026 |
| CVE-2026-48711 | HIGH | 7.0 | SSHFS is a network filesystem client for connecting to SSH servers. From version 1.4 until 3.7.6, SSHFS accepts a bracketed mount source such as [-oProxyCommand=CMD]:/path … | Aug 19, 2026 |
| CVE-2026-47187 | CRITICAL | 9.3 | SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can return absolute symlink targets or … | Aug 19, 2026 |
| CVE-2026-45742 | HIGH | 7.5 | Gotenberg is a Docker-powered stateless API for PDF files. From 8.10.0 until 8.33.0, the newContext function in pkg/modules/api/context.go starts one errgroup.Go goroutine for each multipart … | Aug 19, 2026 |
| CVE-2026-45741 | HIGH | 7.5 | Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, the IsPublicIP function in pkg/gotenberg/outbound.go does not reject the 2002::/16 6to4 prefix, … | Aug 19, 2026 |
| CVE-2026-45274 | UNKNOWN | — | MyBooks is anebook management web server also known as Talebook. In 3.41.2 and earlier, the SignUp.post handler for POST /api/user/sign_up in webserver/handlers/user.py does not enforce … | Aug 19, 2026 |
| CVE-2026-45273 | UNKNOWN | — | MyBooks is an ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post handler for POST /api/admin/settings in webserver/handlers/admin.py applies the … | Aug 19, 2026 |
| CVE-2026-45272 | UNKNOWN | — | MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post handler in webserver/handlers/admin.py accepts … | Aug 19, 2026 |
| CVE-2026-44829 | HIGH | 8.8 | Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, filename handling in pkg/modules/api/context.go uses filepath.Base on Linux, which does not treat … | Aug 19, 2026 |
| CVE-2026-40509 | MEDIUM | 4.3 | OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The web_path GET parameter in the DICOM viewer page is embedded unsanitized … | Aug 19, 2026 |
| CVE-2026-40508 | MEDIUM | 5.4 | OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal template import handler that allows authenticated attackers with Forms Administration permissions to … | Aug 19, 2026 |
| CVE-2026-40507 | MEDIUM | 6.1 | OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal template import handler. The templateHtml GET parameter is reflected into the page … | Aug 19, 2026 |
| CVE-2026-32802 | MEDIUM | 5.3 | Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this … | Aug 19, 2026 |
| CVE-2026-23501 | HIGH | 7.2 | Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A … | Aug 19, 2026 |
| CVE-2026-18756 | UNKNOWN | — | HumHub Community Edition 1.18.4 contains a reflected cross-site scripting vulnerability in the Space membership-request workflow. An attacker can place attacker-controlled button configuration in the options … | Aug 19, 2026 |