Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26387
Total
1955
Critical
7970
High
8222
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-44046 | UNKNOWN | — | Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under default configuration to potentially pollute logs with spoofed … | Jun 19, 2026 |
| CVE-2026-39999 | UNKNOWN | — | Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache … | Jun 19, 2026 |
| CVE-2026-39998 | UNKNOWN | — | Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof identity headers. This issue affects … | Jun 19, 2026 |
| CVE-2026-12104 | UNKNOWN | — | OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25.7.5 on Linux allows an authenticated attacker with configuration … | Jun 19, 2026 |
| CVE-2025-62821 | UNKNOWN | — | Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the reported data size as 0. This causes a … | Jun 19, 2026 |
| CVE-2026-56142 | CRITICAL | 9.9 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible | Jun 19, 2026 |
| CVE-2026-56141 | CRITICAL | 9.8 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible | Jun 19, 2026 |
| CVE-2026-53915 | HIGH | 7.1 | In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration | Jun 19, 2026 |
| CVE-2026-50242 | CRITICAL | 10.0 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible | Jun 19, 2026 |
| CVE-2026-44939 | UNKNOWN | — | A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out … | Jun 19, 2026 |
| CVE-2026-12706 | MEDIUM | 6.5 | A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read pointer into a decompressed buffer, but a subsequent reallocation … | Jun 19, 2026 |
| CVE-2026-11941 | MEDIUM | 5.6 | Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The “quiche_connection_id_iter_next” and “quiche_conn_retired_scid_next” functions would return a pointer to … | Jun 19, 2026 |
| CVE-2026-48777 | UNKNOWN | — | FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1-beta are vulnerable to Path Traversal through the publicPatchHandler in … | Jun 16, 2026 |
| CVE-2026-47750 | HIGH | 7.8 | stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, … | Jun 16, 2026 |
| CVE-2026-47747 | HIGH | 7.8 | stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, … | Jun 16, 2026 |
| CVE-2026-46448 | MEDIUM | 5.4 | In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation. | Jun 16, 2026 |
| CVE-2026-22313 | CRITICAL | 9.1 | The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability … | Jun 16, 2026 |
| CVE-2026-22312 | HIGH | 8.6 | The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to … | Jun 16, 2026 |
| CVE-2026-12425 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center allows Cross-Site Scripting (XSS). This issue affects … | Jun 16, 2026 |
| CVE-2026-12117 | UNKNOWN | — | Improper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated vault member to enumerate social login entry metadata to … | Jun 16, 2026 |
| CVE-2026-12105 | UNKNOWN | — | Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with inherited permissions. | Jun 16, 2026 |
| CVE-2026-11890 | UNKNOWN | — | Improper access control in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to retrieve account discovery scan results. | Jun 16, 2026 |
| CVE-2026-10303 | HIGH | 7.4 | In ServerCo getssl version 2.49 and prior, the ACME challenge token returned to the client was not strictly validated against RFC 8555 before being used … | Jun 16, 2026 |
| CVE-2026-0165 | UNKNOWN | — | In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote … | Jun 16, 2026 |
| CVE-2026-0164 | UNKNOWN | — | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no … | Jun 16, 2026 |