Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47587
Total
3849
Critical
14223
High
13906
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-63649 | UNKNOWN | — | The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and … | Aug 14, 2026 |
| CVE-2026-18932 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 14, 2026 |
| CVE-2026-73683 | HIGH | 8.1 | Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim validation … | Aug 14, 2026 |
| CVE-2026-69414 | HIGH | 7.8 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are … | Aug 14, 2026 |
| CVE-2026-74248 | MEDIUM | 4.3 | OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent … | Aug 14, 2026 |
| CVE-2026-73682 | HIGH | 8.8 | Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url handling that allows authenticated users holding the Manager … | Aug 14, 2026 |
| CVE-2026-71570 | UNKNOWN | — | Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_icagenda` only could enumerate … | Aug 14, 2026 |
| CVE-2026-67366 | UNKNOWN | — | Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the frontend are callable without … | Aug 14, 2026 |
| CVE-2026-50523 | HIGH | 7.8 | Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally. | Aug 14, 2026 |
| CVE-2026-73680 | HIGH | 8.8 | Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute … | Aug 14, 2026 |
| CVE-2026-71571 | UNKNOWN | — | Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 - Backend operators with permissions to access iCagenda could … | Aug 14, 2026 |
| CVE-2026-67365 | UNKNOWN | — | Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session, … | Aug 14, 2026 |
| CVE-2026-64887 | UNKNOWN | — | Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack. This issue affects Airwall: before 4.1. | Aug 14, 2026 |
| CVE-2026-39925 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 14, 2026 |
| CVE-2026-34492 | UNKNOWN | — | External control of file name or path vulnerability in Johnson Controls Airwall allows : File Manipulation. This issue affects Airwall: before 4.1. | Aug 14, 2026 |
| CVE-2026-27871 | UNKNOWN | — | Cwe-327 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Johnson Controls TL280 allows Cryptanalytic Attack. This issue affects TL280: before 5.63. | Aug 14, 2026 |
| CVE-2026-19910 | HIGH | 7.5 | PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of … | Aug 14, 2026 |
| CVE-2026-19909 | HIGH | 7.5 | PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of … | Aug 14, 2026 |
| CVE-2026-19908 | HIGH | 7.1 | PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information and modify configuration on affected installations of PAX … | Aug 14, 2026 |
| CVE-2026-18554 | HIGH | 7.5 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a … | Aug 14, 2026 |
| CVE-2026-18178 | MEDIUM | 5.4 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal. | Aug 14, 2026 |
| CVE-2026-17227 | MEDIUM | 5.4 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special … | Aug 14, 2026 |
| CVE-2026-17209 | MEDIUM | 6.3 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting. | Aug 14, 2026 |
| CVE-2026-17186 | CRITICAL | 9.9 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special … | Aug 14, 2026 |
| CVE-2026-17184 | CRITICAL | 9.8 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name … | Aug 14, 2026 |