Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45339
Total
3649
Critical
13458
High
13386
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-56873 | UNKNOWN | — | Rejected reason: reserved but not needed | Aug 18, 2026 |
| CVE-2026-56872 | UNKNOWN | — | Rejected reason: reserved but not needed | Aug 18, 2026 |
| CVE-2026-56871 | UNKNOWN | — | Rejected reason: reserved but not needed | Aug 18, 2026 |
| CVE-2026-56870 | UNKNOWN | — | Rejected reason: reserved but not needed | Aug 18, 2026 |
| CVE-2026-56869 | UNKNOWN | — | Rejected reason: reserved but not needed | Aug 18, 2026 |
| CVE-2026-56868 | UNKNOWN | — | Rejected reason: reserved but not needed | Aug 18, 2026 |
| CVE-2026-56867 | UNKNOWN | — | Rejected reason: reserved but not needed | Aug 18, 2026 |
| CVE-2026-55593 | MEDIUM | 6.5 | Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php entry point bypasses the centralized request validation in lib/init.php, and Ajax::handle in … | Aug 18, 2026 |
| CVE-2026-55426 | HIGH | 7.8 | linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands. … | Aug 18, 2026 |
| CVE-2026-54543 | MEDIUM | 5.4 | Froxlor is open source server administration software. Prior to 2.3.8, the DomainZones.add API command in lib/Froxlor/Api/Commands/DomainZones.php accepts user-controlled record and type values without rejecting line … | Aug 18, 2026 |
| CVE-2026-54348 | HIGH | 7.2 | Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.php accept an attacker-controlled ipaddress array and store it … | Aug 18, 2026 |
| CVE-2026-54347 | HIGH | 8.7 | Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Api/Commands/DomainZones.php can contain HTML special characters, lib/Froxlor/UI/Callbacks/Text.php returns the … | Aug 18, 2026 |
| CVE-2026-53759 | UNKNOWN | — | linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 4.2.0, db_sqlite.py created SQLite databases at predictable paths in … | Aug 18, 2026 |
| CVE-2026-53458 | UNKNOWN | — | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio backend API handlers in custom_components/blueprint_studio/backend/api.py returned raw … | Aug 18, 2026 |
| CVE-2026-53457 | UNKNOWN | — | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, the legacy stateless terminal command execution path in custom_components/blueprint_studio/backend/terminal_manager.py … | Aug 18, 2026 |
| CVE-2026-53456 | UNKNOWN | — | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio terminal SSH key authentication in custom_components/blueprint_studio/backend/terminal_manager.py wrote … | Aug 18, 2026 |
| CVE-2026-53455 | UNKNOWN | — | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio generated a shell-based Git credential helper in … | Aug 18, 2026 |
| CVE-2026-53454 | UNKNOWN | — | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio configured Git's credential.helper store when saving Git … | Aug 18, 2026 |
| CVE-2026-53453 | UNKNOWN | — | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intended backend API actions to any … | Aug 18, 2026 |
| CVE-2026-52817 | UNKNOWN | — | Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 5.1.0, the shipped assets/sudoers/Debian.sudoers policy allowed the nagios or icinga … | Aug 18, 2026 |
| CVE-2026-52793 | HIGH | 8.1 | Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path in lib/Froxlor/Api/FroxlorRPC.php and FroxlorRPC::validateAuth accepts an API key and secret for … | Aug 18, 2026 |
| CVE-2026-41921 | MEDIUM | 5.4 | Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase suggestion handler that allows authenticated staff users to inject malicious … | Aug 18, 2026 |
| CVE-2026-18504 | MEDIUM | 5.4 | fastify is a fast and low overhead web framework for Node.js. Versions of fastify before 5.12.1 are affected by a schema validation bypass when a … | Aug 18, 2026 |
| CVE-2026-16732 | MEDIUM | 6.1 | fastify is a fast and low overhead web framework for Node.js. Impact: the fix for CVE-2026-3635 added a guard on the forwarded-header reads used to … | Aug 18, 2026 |
| CVE-2026-15571 | HIGH | 7.3 | A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to … | Aug 18, 2026 |