Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
46113
Total
3679
Critical
13638
High
13568
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-50774 | UNKNOWN | — | An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role. | Aug 17, 2026 |
| CVE-2026-50773 | UNKNOWN | — | An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 allows a remote attacker to execute arbtirary code via a crafted .dll file. | Aug 17, 2026 |
| CVE-2026-45698 | HIGH | 7.5 | Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in … | Aug 17, 2026 |
| CVE-2026-17639 | UNKNOWN | — | Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condition that allows an unauthenticated attacker to cause the device … | Aug 17, 2026 |
| CVE-2026-12553 | UNKNOWN | — | HP has identified a potential vulnerability in HP Web Jetadmin (WJA) that may allow an unauthenticated actor to read from or write to arbitrary files … | Aug 17, 2026 |
| CVE-2026-74254 | UNKNOWN | — | Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL … | Aug 17, 2026 |
| CVE-2026-74253 | UNKNOWN | — | Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 - Regular Labs Sourcerer before 14.0.0 processes {source} blocks … | Aug 17, 2026 |
| CVE-2026-73523 | HIGH | 7.5 | COVESA Open1722 through 0.9.2 contains an integer truncation vulnerability in acf-can-listener.c that allows unauthenticated remote attackers to cause the CAN listener to transmit process stack … | Aug 17, 2026 |
| CVE-2026-73522 | HIGH | 7.5 | COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to write past the end of a fixed 15-slot stack … | Aug 17, 2026 |
| CVE-2026-73424 | MEDIUM | 6.5 | Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/integrations/vercel/src/serverless/entrypoint.ts accepts x_astro_path for the public /_isr function … | Aug 17, 2026 |
| CVE-2026-71980 | HIGH | 7.5 | Belledonne Communications bcg729 through 1.1.2 contains an out-of-bounds read vulnerability in the decodeSIDframe() function in src/cng.c that allows unauthenticated network-adjacent attackers to trigger a heap … | Aug 17, 2026 |
| CVE-2026-71979 | HIGH | 7.5 | INDI (Instrument Neutral Distributed Interface) indiserver through 2.2.4.2, fixed in commit 96bbd7f, contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to crash … | Aug 17, 2026 |
| CVE-2026-71491 | UNKNOWN | — | sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-only statements before the MAX_GROUPING_TOKENS guard, causing quadratic … | Aug 17, 2026 |
| CVE-2026-68520 | MEDIUM | 5.3 | Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in glances/config.py checks only option names and exposes public_username and credentials embedded in … | Aug 17, 2026 |
| CVE-2026-68519 | UNKNOWN | — | Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, GlancesActions.run() in glances/actions.py ignores --disable-config-exec for on-alert action commands and invokes secure_popen() with shell … | Aug 17, 2026 |
| CVE-2026-62982 | HIGH | 8.8 | Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_mustache_dict() in glances/actions.py skips nested list and dictionary strings such as process cmdline … | Aug 17, 2026 |
| CVE-2026-59903 | MEDIUM | 6.5 | Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie with … | Aug 17, 2026 |
| CVE-2026-59902 | HIGH | 7.5 | Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedBytes, allowing unauthenticated … | Aug 17, 2026 |
| CVE-2026-59894 | UNKNOWN | — | sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and output_format='php' … | Aug 17, 2026 |
| CVE-2026-59893 | HIGH | 7.5 | sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted … | Aug 17, 2026 |
| CVE-2026-54284 | UNKNOWN | — | sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed … | Aug 17, 2026 |
| CVE-2026-51346 | CRITICAL | 9.1 | SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensitive information via … | Aug 17, 2026 |
| CVE-2026-50772 | UNKNOWN | — | An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function. | Aug 17, 2026 |
| CVE-2026-50771 | MEDIUM | 6.1 | Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbtirary code via the Email Notification, Create Evaluation Sets … | Aug 17, 2026 |
| CVE-2026-50770 | UNKNOWN | — | An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted request. | Aug 17, 2026 |