Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47022
Total
3783
Critical
14020
High
13725
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-66272 | MEDIUM | 5.3 | Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially … | Aug 14, 2026 |
| CVE-2026-66271 | HIGH | 7.2 | Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote … | Aug 14, 2026 |
| CVE-2026-66270 | HIGH | 7.2 | Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote … | Aug 14, 2026 |
| CVE-2026-63702 | MEDIUM | 6.3 | Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially … | Aug 14, 2026 |
| CVE-2026-63701 | MEDIUM | 6.3 | Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could … | Aug 14, 2026 |
| CVE-2026-63700 | HIGH | 7.8 | Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with local access could potentially exploit … | Aug 14, 2026 |
| CVE-2026-57472 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file management functionality of the … | Aug 14, 2026 |
| CVE-2026-57471 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file management functionality of the … | Aug 14, 2026 |
| CVE-2026-57469 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the web-based configuration backend of KUNBUS PiCtory in version 2.16.0 that allows a … | Aug 14, 2026 |
| CVE-2026-53970 | HIGH | 7.5 | ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers to execute arbitrary code by … | Aug 14, 2026 |
| CVE-2026-19884 | UNKNOWN | — | In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the folder first. … | Aug 14, 2026 |
| CVE-2026-19837 | LOW | 2.7 | A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/search of the component Customer Search. … | Aug 14, 2026 |
| CVE-2026-19836 | MEDIUM | 4.3 | A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/customers/view of … | Aug 14, 2026 |
| CVE-2026-19835 | LOW | 3.8 | A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. … | Aug 14, 2026 |
| CVE-2026-19834 | MEDIUM | 4.7 | A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonation … | Aug 14, 2026 |
| CVE-2026-16772 | HIGH | 8.1 | In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges. This … | Aug 14, 2026 |
| CVE-2026-13198 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the event notification functionality of KUNBUS piControl … | Aug 14, 2026 |
| CVE-2026-13197 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the configuration and process-image management functionality of … | Aug 14, 2026 |
| CVE-2026-13196 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated … | Aug 14, 2026 |
| CVE-2026-13002 | MEDIUM | 4.4 | A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the … | Aug 14, 2026 |
| CVE-2026-69101 | HIGH | 7.7 | Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by … | Aug 14, 2026 |
| CVE-2026-58224 | MEDIUM | 6.5 | A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets … | Aug 14, 2026 |
| CVE-2026-19880 | UNKNOWN | — | Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender … | Aug 14, 2026 |
| CVE-2026-19879 | MEDIUM | 5.3 | A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method performs a silent narrowing cast from … | Aug 14, 2026 |
| CVE-2026-73633 | HIGH | 7.5 | Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the … | Aug 14, 2026 |