Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26387
Total
1955
Critical
7970
High
8222
Medium
CVE ID Severity Score Description Published
CVE-2026-44046 UNKNOWN Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under default configuration to potentially pollute logs with spoofed … Jun 19, 2026
CVE-2026-39999 UNKNOWN Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache … Jun 19, 2026
CVE-2026-39998 UNKNOWN Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof identity headers. This issue affects … Jun 19, 2026
CVE-2026-12104 UNKNOWN OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25.7.5 on Linux allows an authenticated attacker with configuration … Jun 19, 2026
CVE-2025-62821 UNKNOWN Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the reported data size as 0. This causes a … Jun 19, 2026
CVE-2026-56142 CRITICAL 9.9 In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible Jun 19, 2026
CVE-2026-56141 CRITICAL 9.8 In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible Jun 19, 2026
CVE-2026-53915 HIGH 7.1 In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration Jun 19, 2026
CVE-2026-50242 CRITICAL 10.0 In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible Jun 19, 2026
CVE-2026-44939 UNKNOWN A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out … Jun 19, 2026
CVE-2026-12706 MEDIUM 6.5 A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read pointer into a decompressed buffer, but a subsequent reallocation … Jun 19, 2026
CVE-2026-11941 MEDIUM 5.6 Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The “quiche_connection_id_iter_next” and “quiche_conn_retired_scid_next” functions would return a pointer to … Jun 19, 2026
CVE-2026-48777 UNKNOWN FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1-beta are vulnerable to Path Traversal through the publicPatchHandler in … Jun 16, 2026
CVE-2026-47750 HIGH 7.8 stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, … Jun 16, 2026
CVE-2026-47747 HIGH 7.8 stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, … Jun 16, 2026
CVE-2026-46448 MEDIUM 5.4 In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation. Jun 16, 2026
CVE-2026-22313 CRITICAL 9.1 The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability … Jun 16, 2026
CVE-2026-22312 HIGH 8.6 The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to … Jun 16, 2026
CVE-2026-12425 UNKNOWN Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center allows Cross-Site Scripting (XSS). This issue affects … Jun 16, 2026
CVE-2026-12117 UNKNOWN Improper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated vault member to enumerate social login entry metadata to … Jun 16, 2026
CVE-2026-12105 UNKNOWN Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with inherited permissions. Jun 16, 2026
CVE-2026-11890 UNKNOWN Improper access control in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to retrieve account discovery scan results. Jun 16, 2026
CVE-2026-10303 HIGH 7.4 In ServerCo getssl version 2.49 and prior, the ACME challenge token returned to the client was not strictly validated against RFC 8555 before being used … Jun 16, 2026
CVE-2026-0165 UNKNOWN In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote … Jun 16, 2026
CVE-2026-0164 UNKNOWN In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no … Jun 16, 2026