Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

47180
Total
3801
Critical
14071
High
13766
Medium
CVE ID Severity Score Description Published
CVE-2026-17079 MEDIUM 6.3 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable … Aug 14, 2026
CVE-2026-16915 HIGH 7.5 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation. Aug 14, 2026
CVE-2026-16905 MEDIUM 5.3 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication. Aug 14, 2026
CVE-2026-16879 HIGH 8.8 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied … Aug 14, 2026
CVE-2026-16708 HIGH 8.3 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration. Aug 14, 2026
CVE-2026-73679 HIGH 7.2 ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute arbitrary PHP code by storing a … Aug 14, 2026
CVE-2026-73678 CRITICAL 10.0 MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting … Aug 14, 2026
CVE-2026-50029 MEDIUM 5.3 js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a key already exists in a parser-built container with `if … Aug 14, 2026
CVE-2026-50027 CRITICAL 9.8 mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, … Aug 14, 2026
CVE-2026-49457 CRITICAL 9.1 erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The … Aug 14, 2026
CVE-2026-45699 HIGH 7.5 Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in … Aug 14, 2026
CVE-2026-19188 CRITICAL 10.0 A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature … Aug 14, 2026
CVE-2026-18403 UNKNOWN LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central … Aug 14, 2026
CVE-2025-7639 UNKNOWN The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution … Aug 14, 2026
CVE-2026-73850 UNKNOWN Emlog is an open source website building system. In 2.6.20 and earlier, there is a SQL injection vulnerability in the queryDatabase function in ai.php. Aug 14, 2026
CVE-2026-73849 CRITICAL 9.8 Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the … Aug 14, 2026
CVE-2026-73847 MEDIUM 6.8 Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a … Aug 14, 2026
CVE-2026-72970 HIGH 8.3 Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Aug 14, 2026
CVE-2026-63361 UNKNOWN LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text and name query parameters are passed … Aug 14, 2026
CVE-2026-49282 MEDIUM 5.1 Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends … Aug 14, 2026
CVE-2026-49263 UNKNOWN Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-controlled raw WASM instruction bytes through the public `cs_disasm()` and `cs_disasm_iter()` APIs. … Aug 14, 2026
CVE-2026-48528 CRITICAL 9.8 Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in … Aug 14, 2026
CVE-2026-19847 HIGH 8.8 A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so. The manipulation … Aug 14, 2026
CVE-2026-19846 HIGH 8.8 A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the … Aug 14, 2026
CVE-2026-19682 CRITICAL 9.9 A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating … Aug 14, 2026