Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
46113
Total
3679
Critical
13638
High
13568
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-64788 | MEDIUM | 5.4 | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web … | Aug 17, 2026 |
| CVE-2026-64787 | MEDIUM | 6.5 | A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted … | Aug 17, 2026 |
| CVE-2026-64784 | MEDIUM | 4.3 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, … | Aug 17, 2026 |
| CVE-2026-64782 | LOW | 3.1 | A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS … | Aug 17, 2026 |
| CVE-2026-64781 | MEDIUM | 4.3 | The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe … | Aug 17, 2026 |
| CVE-2026-64780 | MEDIUM | 4.3 | The issue was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. … | Aug 17, 2026 |
| CVE-2026-64779 | LOW | 3.1 | A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS … | Aug 17, 2026 |
| CVE-2026-64778 | MEDIUM | 6.5 | The issue was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. … | Aug 17, 2026 |
| CVE-2026-64760 | MEDIUM | 5.5 | An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An app may be able to leak … | Aug 17, 2026 |
| CVE-2026-64715 | MEDIUM | 6.5 | A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS … | Aug 17, 2026 |
| CVE-2026-63178 | MEDIUM | 6.5 | Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Edition's PATCH /manage/admin/user-group/{user_group_id} and POST /manage/admin/user-group/{user_group_id}/add-users endpoints in ee/onyx/server/user_group/api.py call update_user_group and add_users_to_user_group in … | Aug 17, 2026 |
| CVE-2026-56677 | HIGH | 8.6 | 9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the user-controlled issuerUrl parameter to fetchOidcDiscovery() … | Aug 17, 2026 |
| CVE-2026-54385 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 17, 2026 |
| CVE-2026-51977 | CRITICAL | 9.1 | An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the RSA private … | Aug 17, 2026 |
| CVE-2026-45791 | MEDIUM | 5.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's user.update procedure in apps/dokploy/server/api/routers/user.ts updates account.password without deleting other rows from … | Aug 17, 2026 |
| CVE-2026-45790 | HIGH | 8.0 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC procedure in apps/dokploy/server/api/routers/organization.ts allows a user with member:create permission … | Aug 17, 2026 |
| CVE-2026-43795 | MEDIUM | 4.3 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe … | Aug 17, 2026 |
| CVE-2026-43794 | HIGH | 8.8 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, … | Aug 17, 2026 |
| CVE-2026-43667 | MEDIUM | 6.5 | A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An attacker in a privileged network … | Aug 17, 2026 |
| CVE-2026-42163 | CRITICAL | 9.8 | Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI … | Aug 17, 2026 |
| CVE-2026-28984 | MEDIUM | 4.3 | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. Processing maliciously crafted web content may lead … | Aug 17, 2026 |
| CVE-2026-11817 | UNKNOWN | — | This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org … | Aug 17, 2026 |
| CVE-2026-10080 | MEDIUM | 6.5 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSocket command field types which allows an authenticated user to crash … | Aug 17, 2026 |
| CVE-2026-75531 | UNKNOWN | — | Pandora contains a stored cross-site scripting (XSS) vulnerability in the rendering of URL observables. A URL extracted from or associated with an analyzed file was … | Aug 17, 2026 |
| CVE-2026-75529 | UNKNOWN | — | Pandora is affected by a stored cross-site scripting vulnerability in the PDF download functionality. The /task-download/<task_id>/.../pdf endpoint verifies that the submitted file is a PDF … | Aug 17, 2026 |