Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47022
Total
3783
Critical
14020
High
13725
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-12366 | HIGH | 8.8 | Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an object's storage (k_free(dyn->data)) once its reference count reaches zero, after running a per-object-type cleanup. The … | Aug 14, 2026 |
| CVE-2026-12365 | MEDIUM | 5.8 | A use-after-free exists in the Zephyr second-generation work queue (kernel/work.c) in the handling of delayable work timeouts. When a delayable work item's timeout has been … | Aug 14, 2026 |
| CVE-2026-12364 | HIGH | 8.4 | The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was a pure pass-through: it forwarded the caller-supplied source, desc, package, and data arguments directly to the kernel-mode … | Aug 14, 2026 |
| CVE-2026-12363 | MEDIUM | 4.2 | The LoRaWAN Fragmented Data Block Transport service (subsys/lorawan/services/frag_transport.c) does not validate the fragment counter in a received DATA_FRAGMENT command before forwarding it to the configured … | Aug 14, 2026 |
| CVE-2026-73846 | MEDIUM | 6.5 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request parameters with unescaped ampersand, equals-sign, … | Aug 14, 2026 |
| CVE-2026-73845 | MEDIUM | 5.3 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaServer to … | Aug 14, 2026 |
| CVE-2026-73844 | LOW | 3.7 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception … | Aug 14, 2026 |
| CVE-2026-73107 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 14, 2026 |
| CVE-2026-49989 | UNKNOWN | — | CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they … | Aug 14, 2026 |
| CVE-2026-49986 | UNKNOWN | — | The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code … | Aug 14, 2026 |
| CVE-2026-49826 | UNKNOWN | — | Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL … | Aug 14, 2026 |
| CVE-2026-47766 | UNKNOWN | — | crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs `/dev` … | Aug 14, 2026 |
| CVE-2026-47192 | UNKNOWN | — | kas is a setup tool for bitbake based projects. Starting in version 4.8 and prior to version 5.3, kas checks out and processes repositories regarding … | Aug 14, 2026 |
| CVE-2026-47191 | UNKNOWN | — | kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git commit ID (SHA-1 or SHA-256) to … | Aug 14, 2026 |
| CVE-2026-46603 | HIGH | 7.5 | VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows … | Aug 14, 2026 |
| CVE-2026-46439 | HIGH | 7.8 | compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in … | Aug 14, 2026 |
| CVE-2026-46380 | MEDIUM | 6.7 | compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to … | Aug 14, 2026 |
| CVE-2026-19845 | HIGH | 8.8 | A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of … | Aug 14, 2026 |
| CVE-2026-19844 | HIGH | 8.8 | A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component ipv6.so. Performing a … | Aug 14, 2026 |
| CVE-2026-19841 | LOW | 3.1 | A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes … | Aug 14, 2026 |
| CVE-2026-19839 | MEDIUM | 4.7 | A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue affects the function save_doctor of the file /save_file.php. The manipulation results in … | Aug 14, 2026 |
| CVE-2026-19838 | MEDIUM | 4.3 | A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend … | Aug 14, 2026 |
| CVE-2026-19628 | HIGH | 7.2 | A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying … | Aug 14, 2026 |
| CVE-2026-19626 | CRITICAL | 9.9 | A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted … | Aug 14, 2026 |
| CVE-2023-7347 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 14, 2026 |