Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26398
Total
1955
Critical
7975
High
8226
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-42932 | MEDIUM | 5.3 | Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predictable and enumerable identifier space. Because the platform also exposes an … | Jun 12, 2026 |
| CVE-2026-42306 | HIGH | 7.2 | Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to … | Jun 12, 2026 |
| CVE-2026-41568 | MEDIUM | 6.1 | Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to … | Jun 12, 2026 |
| CVE-2026-28742 | CRITICAL | 9.8 | Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmware image. Once this salt is recovered from any … | Jun 12, 2026 |
| CVE-2026-12143 | HIGH | 7.5 | form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim … | Jun 12, 2026 |
| CVE-2026-12043 | HIGH | 8.8 | Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to … | Jun 12, 2026 |
| CVE-2026-10715 | UNKNOWN | — | Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autosave endpoint. A low-privileged authenticated user can send an arbitrary post_id to POST … | Jun 12, 2026 |
| CVE-2026-53406 | HIGH | 7.8 | Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to enable an … | Jun 12, 2026 |
| CVE-2026-48558 | CRITICAL | 10.0 | SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity … | Jun 12, 2026 |
| CVE-2026-48165 | HIGH | 8.0 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 … | Jun 12, 2026 |
| CVE-2026-48163 | HIGH | 8.0 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 … | Jun 12, 2026 |
| CVE-2026-47965 | HIGH | 7.8 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of … | Jun 12, 2026 |
| CVE-2026-47225 | UNKNOWN | — | Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is a cache isolation issue affecting search requests that use both … | Jun 12, 2026 |
| CVE-2026-47223 | MEDIUM | 5.4 | NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.0.1698.0, a heap out-of-bounds read exists in the … | Jun 12, 2026 |
| CVE-2026-47216 | UNKNOWN | — | Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is an unauthenticated denial-of-service vulnerability in the /multi_search endpoint. A specially … | Jun 12, 2026 |
| CVE-2026-44173 | MEDIUM | 5.0 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 … | Jun 12, 2026 |
| CVE-2026-44172 | UNKNOWN | — | MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it … | Jun 12, 2026 |
| CVE-2026-44171 | MEDIUM | 6.3 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 … | Jun 12, 2026 |
| CVE-2026-44170 | UNKNOWN | — | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 … | Jun 12, 2026 |
| CVE-2026-44169 | MEDIUM | 4.3 | MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting … | Jun 12, 2026 |
| CVE-2026-44168 | HIGH | 8.0 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 … | Jun 12, 2026 |
| CVE-2026-7387 | HIGH | 8.8 | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authorization when setting the scheme_admin flag … | Jun 12, 2026 |
| CVE-2026-7184 | MEDIUM | 6.5 | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API response on PATCH operations, which allows authenticated … | Jun 12, 2026 |
| CVE-2026-6961 | HIGH | 7.6 | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to sanitize FileInfo.Name received from federated peers during shared … | Jun 12, 2026 |
| CVE-2026-6739 | MEDIUM | 6.7 | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-level permission when patching protected default system roles, … | Jun 12, 2026 |