Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26391
Total
1955
Critical
7971
High
8223
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-47749 | HIGH | 7.8 | stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. Versions prior to master-584-0a7ae07 are … | Jun 16, 2026 |
| CVE-2026-47748 | MEDIUM | 5.5 | stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. Versions prior to master-584-0a7ae07 are … | Jun 16, 2026 |
| CVE-2026-10748 | UNKNOWN | — | An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user … | Jun 16, 2026 |
| CVE-2024-39575 | HIGH | 7.4 | update_disk_psu_baseline.sh requires password in plain text | Jun 16, 2026 |
| CVE-2026-53776 | CRITICAL | 9.1 | Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the unconditional setting of validate_exp = false … | Jun 16, 2026 |
| CVE-2026-44932 | HIGH | 8.8 | Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server … | Jun 16, 2026 |
| CVE-2026-42089 | HIGH | 8.6 | Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator is resolved. Versions 2.9.0 through 6.0.0 … | Jun 16, 2026 |
| CVE-2026-39927 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Jun 16, 2026 |
| CVE-2026-39926 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Jun 16, 2026 |
| CVE-2026-24228 | HIGH | 7.8 | NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability may lead … | Jun 16, 2026 |
| CVE-2026-24155 | HIGH | 7.8 | NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, … | Jun 16, 2026 |
| CVE-2026-12412 | UNKNOWN | — | Rejected reason: loading template... | Jun 16, 2026 |
| CVE-2026-12003 | UNKNOWN | — | To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build … | Jun 16, 2026 |
| CVE-2026-10649 | HIGH | 8.6 | A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a … | Jun 16, 2026 |
| CVE-2025-71261 | HIGH | 8.6 | An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse … | Jun 16, 2026 |
| CVE-2024-38487 | HIGH | 7.0 | api-gateway container running with root privilege would allow an attacker to escape the container and access host system to perform unintended actions. | Jun 16, 2026 |
| CVE-2024-30476 | MEDIUM | 5.4 | PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager. A remote authenticated low-privileged malicious actor could potentially exploit this vulnerability, it could lead … | Jun 16, 2026 |
| CVE-2024-24909 | HIGH | 8.8 | Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in the gateway plugin. A remote authenticated user could potentially exploit … | Jun 16, 2026 |
| CVE-2024-22451 | MEDIUM | 6.7 | Dell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious … | Jun 16, 2026 |
| CVE-2026-9307 | UNKNOWN | — | A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which … | Jun 16, 2026 |
| CVE-2026-48780 | HIGH | 8.2 | Forem is open source software for building communities. Prior to commit a2ab6d4, a maliciously crafted email address could allow an attacker to bypass domain allowlist … | Jun 16, 2026 |
| CVE-2026-47684 | HIGH | 7.7 | Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.3.0, the private IP blocklist regex used in … | Jun 16, 2026 |
| CVE-2026-12398 | HIGH | 7.5 | A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitized git ref names (branch/tag names) … | Jun 16, 2026 |
| CVE-2026-11317 | UNKNOWN | — | A denial of service security issue exists in the affected product. The security issue stems from a fault occurring when a crafted CIP message is … | Jun 16, 2026 |
| CVE-2026-10831 | UNKNOWN | — | A denial-of-service vulnerability exists in NPort devices because of improper access control on the command port. The command interface does not properly validate whether a … | Jun 16, 2026 |