Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47180
Total
3801
Critical
14071
High
13766
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-17079 | MEDIUM | 6.3 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable … | Aug 14, 2026 |
| CVE-2026-16915 | HIGH | 7.5 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation. | Aug 14, 2026 |
| CVE-2026-16905 | MEDIUM | 5.3 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication. | Aug 14, 2026 |
| CVE-2026-16879 | HIGH | 8.8 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied … | Aug 14, 2026 |
| CVE-2026-16708 | HIGH | 8.3 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration. | Aug 14, 2026 |
| CVE-2026-73679 | HIGH | 7.2 | ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute arbitrary PHP code by storing a … | Aug 14, 2026 |
| CVE-2026-73678 | CRITICAL | 10.0 | MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting … | Aug 14, 2026 |
| CVE-2026-50029 | MEDIUM | 5.3 | js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a key already exists in a parser-built container with `if … | Aug 14, 2026 |
| CVE-2026-50027 | CRITICAL | 9.8 | mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, … | Aug 14, 2026 |
| CVE-2026-49457 | CRITICAL | 9.1 | erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The … | Aug 14, 2026 |
| CVE-2026-45699 | HIGH | 7.5 | Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in … | Aug 14, 2026 |
| CVE-2026-19188 | CRITICAL | 10.0 | A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature … | Aug 14, 2026 |
| CVE-2026-18403 | UNKNOWN | — | LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central … | Aug 14, 2026 |
| CVE-2025-7639 | UNKNOWN | — | The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution … | Aug 14, 2026 |
| CVE-2026-73850 | UNKNOWN | — | Emlog is an open source website building system. In 2.6.20 and earlier, there is a SQL injection vulnerability in the queryDatabase function in ai.php. | Aug 14, 2026 |
| CVE-2026-73849 | CRITICAL | 9.8 | Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the … | Aug 14, 2026 |
| CVE-2026-73847 | MEDIUM | 6.8 | Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a … | Aug 14, 2026 |
| CVE-2026-72970 | HIGH | 8.3 | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | Aug 14, 2026 |
| CVE-2026-63361 | UNKNOWN | — | LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text and name query parameters are passed … | Aug 14, 2026 |
| CVE-2026-49282 | MEDIUM | 5.1 | Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends … | Aug 14, 2026 |
| CVE-2026-49263 | UNKNOWN | — | Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-controlled raw WASM instruction bytes through the public `cs_disasm()` and `cs_disasm_iter()` APIs. … | Aug 14, 2026 |
| CVE-2026-48528 | CRITICAL | 9.8 | Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in … | Aug 14, 2026 |
| CVE-2026-19847 | HIGH | 8.8 | A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so. The manipulation … | Aug 14, 2026 |
| CVE-2026-19846 | HIGH | 8.8 | A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the … | Aug 14, 2026 |
| CVE-2026-19682 | CRITICAL | 9.9 | A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating … | Aug 14, 2026 |