Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26401
Total
1955
Critical
7975
High
8228
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-40677 | UNKNOWN | — | The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle attack, potentially leading to arbitrary code execution. | Jun 12, 2026 |
| CVE-2026-8694 | MEDIUM | 5.3 | Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification of user-defined REST endpoints. | Jun 12, 2026 |
| CVE-2026-7368 | HIGH | 8.1 | The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the shared hard-coded credentials or legitimate per-user credentials, can … | Jun 12, 2026 |
| CVE-2026-6853 | CRITICAL | 9.8 | Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. Pause+ Mobile App allows Authentication Bypass. This … | Jun 12, 2026 |
| CVE-2026-6211 | HIGH | 8.7 | Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Accessing Functionality Not Properly Constrained by ACLs. This issue … | Jun 12, 2026 |
| CVE-2026-54133 | CRITICAL | 9.8 | jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. … | Jun 12, 2026 |
| CVE-2026-53787 | CRITICAL | 9.8 | Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to … | Jun 12, 2026 |
| CVE-2026-53722 | UNKNOWN | — | Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <NuxtLink> did not validate the URL scheme of values bound … | Jun 12, 2026 |
| CVE-2026-53721 | UNKNOWN | — | Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule middleware … | Jun 12, 2026 |
| CVE-2026-47739 | UNKNOWN | — | Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS in Note was possible due to lack of sanitization. This … | Jun 12, 2026 |
| CVE-2026-47244 | MEDIUM | 5.3 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, DefaultHttp2Connection.DefaultEndpoint initialises maxActiveStreams/maxStreams to Integer.MAX_VALUE, and … | Jun 12, 2026 |
| CVE-2026-47210 | CRITICAL | 9.8 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbitrary code execution in the host … | Jun 12, 2026 |
| CVE-2026-47209 | HIGH | 8.6 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in bridge.js (line 1231) ignores the receiver parameter and unconditionally … | Jun 12, 2026 |
| CVE-2026-47208 | CRITICAL | 10.0 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code … | Jun 12, 2026 |
| CVE-2026-47141 | UNKNOWN | — | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM exposes some process-wide observability builtins when they are allowed through require.builtin. The … | Jun 12, 2026 |
| CVE-2026-47140 | CRITICAL | 10.0 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins such as module, worker_threads, cluster, vm, repl, … | Jun 12, 2026 |
| CVE-2026-47139 | HIGH | 8.6 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins from the wildcard builtin option. With this … | Jun 12, 2026 |
| CVE-2026-47137 | CRITICAL | 10.0 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) introduced a check in nodevm.js line 263 that … | Jun 12, 2026 |
| CVE-2026-47135 | HIGH | 8.7 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only intercepts 2 of 9 dangerous Node.js cross-realm symbols. … | Jun 12, 2026 |
| CVE-2026-47131 | CRITICAL | 10.0 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__"), Buffer.call.call({}.__lookupSetter__, Buffer, "__proto__"), and Node.js's ERR_INVALID_ARG_TYPE Error, the … | Jun 12, 2026 |
| CVE-2026-46340 | HIGH | 7.5 | Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final and 4.2.15.Final, for each non-complete … | Jun 12, 2026 |
| CVE-2026-45674 | HIGH | 8.7 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the … | Jun 12, 2026 |
| CVE-2026-45673 | MEDIUM | 6.8 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DNS resolver uses a predictable … | Jun 12, 2026 |
| CVE-2026-45536 | MEDIUM | 4.0 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to `char control[CMSG_SPACE(sizeof(int))]` … | Jun 12, 2026 |
| CVE-2026-45416 | HIGH | 7.5 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake … | Jun 12, 2026 |