Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47180
Total
3801
Critical
14071
High
13766
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-13197 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the configuration and process-image management functionality of … | Aug 14, 2026 |
| CVE-2026-13196 | UNKNOWN | — | Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated … | Aug 14, 2026 |
| CVE-2026-13002 | MEDIUM | 4.4 | A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the … | Aug 14, 2026 |
| CVE-2026-69101 | HIGH | 7.7 | Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by … | Aug 14, 2026 |
| CVE-2026-58224 | MEDIUM | 6.5 | A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets allows malformed packets … | Aug 14, 2026 |
| CVE-2026-19880 | UNKNOWN | — | Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender … | Aug 14, 2026 |
| CVE-2026-19879 | MEDIUM | 5.3 | A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method performs a silent narrowing cast from … | Aug 14, 2026 |
| CVE-2026-73633 | HIGH | 7.5 | Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSON request body, the … | Aug 14, 2026 |
| CVE-2026-53472 | MEDIUM | 6.3 | A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialUrl` field allows an authenticated attacker to store a malicious `javascript:` URL. When a victim … | Aug 14, 2026 |
| CVE-2026-1621 | MEDIUM | 5.3 | Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality allows Exploitation of Trusted Identifiers. This issue affects E-Municipality: from 20251127 before 20260204. | Aug 14, 2026 |
| CVE-2026-19871 | UNKNOWN | — | Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee … | Aug 14, 2026 |
| CVE-2026-19830 | MEDIUM | 5.3 | A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of the file /etc/bftpd.conf of the component bftpd. The manipulation of the … | Aug 14, 2026 |
| CVE-2026-19829 | MEDIUM | 4.3 | A security flaw has been discovered in 648540858 wvp-GB28181-pro 2.7.4-20260107. This vulnerability affects unknown code of the file LogController.java of the component Log File Download … | Aug 14, 2026 |
| CVE-2026-19828 | MEDIUM | 6.3 | A vulnerability was identified in 648540858 wvp-GB28181-pro 2.7.4-20260107. This affects an unknown part of the file PlayController.java of the component Snapshot Endpoint. The manipulation of … | Aug 14, 2026 |
| CVE-2026-19827 | MEDIUM | 5.3 | A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStream of the file /admin/controller/JobLogController.java of the component logDetailCat Endpoint. … | Aug 14, 2026 |
| CVE-2026-19768 | HIGH | 8.1 | Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings … | Aug 14, 2026 |
| CVE-2026-73673 | HIGH | 8.8 | Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authentication … | Aug 14, 2026 |
| CVE-2026-19870 | UNKNOWN | — | Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to … | Aug 14, 2026 |
| CVE-2026-19826 | HIGH | 7.3 | A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The … | Aug 14, 2026 |
| CVE-2026-19825 | HIGH | 7.3 | A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_service. The … | Aug 14, 2026 |
| CVE-2026-19824 | HIGH | 8.8 | A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. The affected element is the function ipMacBindListStore of the file /goform/addIpMacBind. Executing a manipulation of the … | Aug 14, 2026 |
| CVE-2026-19823 | HIGH | 8.8 | A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. Impacted is the function formQOSRuleDel of the file /goform/delQos of the component QoS Rule Deletion. … | Aug 14, 2026 |
| CVE-2026-73630 | MEDIUM | 5.8 | SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/filetree/authFilePublishAccess endpoint, which is registered with CheckAuth only and is reachable anonymously. The endpoint never … | Aug 14, 2026 |
| CVE-2026-73051 | UNKNOWN | — | actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated … | Aug 14, 2026 |
| CVE-2026-73049 | MEDIUM | 5.8 | SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getAttributeViewBacklinks endpoint that consults the forbidden access list instead of the visibility list when … | Aug 14, 2026 |