Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47022
Total
3783
Critical
14020
High
13725
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-50027 | CRITICAL | 9.8 | mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, … | Aug 14, 2026 |
| CVE-2026-49457 | CRITICAL | 9.1 | erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The … | Aug 14, 2026 |
| CVE-2026-45699 | HIGH | 7.5 | Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in … | Aug 14, 2026 |
| CVE-2026-19188 | CRITICAL | 10.0 | A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature … | Aug 14, 2026 |
| CVE-2026-18403 | UNKNOWN | — | LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central … | Aug 14, 2026 |
| CVE-2025-7639 | UNKNOWN | — | The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution … | Aug 14, 2026 |
| CVE-2026-73850 | UNKNOWN | — | Emlog is an open source website building system. In 2.6.20 and earlier, there is a SQL injection vulnerability in the queryDatabase function in ai.php. | Aug 14, 2026 |
| CVE-2026-73849 | CRITICAL | 9.8 | Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the … | Aug 14, 2026 |
| CVE-2026-73847 | MEDIUM | 6.8 | Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a … | Aug 14, 2026 |
| CVE-2026-72970 | HIGH | 8.3 | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | Aug 14, 2026 |
| CVE-2026-63361 | UNKNOWN | — | LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text and name query parameters are passed … | Aug 14, 2026 |
| CVE-2026-49282 | MEDIUM | 5.1 | Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends … | Aug 14, 2026 |
| CVE-2026-49263 | UNKNOWN | — | Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-controlled raw WASM instruction bytes through the public `cs_disasm()` and `cs_disasm_iter()` APIs. … | Aug 14, 2026 |
| CVE-2026-48528 | CRITICAL | 9.8 | Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in … | Aug 14, 2026 |
| CVE-2026-19847 | HIGH | 8.8 | A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so. The manipulation … | Aug 14, 2026 |
| CVE-2026-19846 | HIGH | 8.8 | A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the … | Aug 14, 2026 |
| CVE-2026-19682 | CRITICAL | 9.9 | A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating … | Aug 14, 2026 |
| CVE-2026-19681 | CRITICAL | 9.9 | An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted … | Aug 14, 2026 |
| CVE-2026-19680 | HIGH | 7.1 | A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database. | Aug 14, 2026 |
| CVE-2026-19679 | HIGH | 8.8 | An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue. | Aug 14, 2026 |
| CVE-2026-19639 | MEDIUM | 4.3 | An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope. | Aug 14, 2026 |
| CVE-2026-19636 | MEDIUM | 5.3 | An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a security control. This has been … | Aug 14, 2026 |
| CVE-2026-19635 | HIGH | 8.8 | A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with … | Aug 14, 2026 |
| CVE-2026-19631 | MEDIUM | 4.9 | A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to … | Aug 14, 2026 |
| CVE-2026-19629 | HIGH | 8.1 | A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group … | Aug 14, 2026 |