Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47587
Total
3849
Critical
14223
High
13906
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-63361 | UNKNOWN | — | LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text and name query parameters are passed … | Aug 14, 2026 |
| CVE-2026-49282 | MEDIUM | 5.1 | Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends … | Aug 14, 2026 |
| CVE-2026-49263 | UNKNOWN | — | Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-controlled raw WASM instruction bytes through the public `cs_disasm()` and `cs_disasm_iter()` APIs. … | Aug 14, 2026 |
| CVE-2026-48528 | CRITICAL | 9.8 | Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in … | Aug 14, 2026 |
| CVE-2026-19847 | HIGH | 8.8 | A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so. The manipulation … | Aug 14, 2026 |
| CVE-2026-19846 | HIGH | 8.8 | A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the … | Aug 14, 2026 |
| CVE-2026-19682 | CRITICAL | 9.9 | A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating … | Aug 14, 2026 |
| CVE-2026-19681 | CRITICAL | 9.9 | An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted … | Aug 14, 2026 |
| CVE-2026-19680 | HIGH | 7.1 | A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database. | Aug 14, 2026 |
| CVE-2026-19679 | HIGH | 8.8 | An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue. | Aug 14, 2026 |
| CVE-2026-19639 | MEDIUM | 4.3 | An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope. | Aug 14, 2026 |
| CVE-2026-19636 | MEDIUM | 5.3 | An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a security control. This has been … | Aug 14, 2026 |
| CVE-2026-19635 | HIGH | 8.8 | A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with … | Aug 14, 2026 |
| CVE-2026-19631 | MEDIUM | 4.9 | A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to … | Aug 14, 2026 |
| CVE-2026-19629 | HIGH | 8.1 | A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group … | Aug 14, 2026 |
| CVE-2026-12366 | HIGH | 8.8 | Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an object's storage (k_free(dyn->data)) once its reference count reaches zero, after running a per-object-type cleanup. The … | Aug 14, 2026 |
| CVE-2026-12365 | MEDIUM | 5.8 | A use-after-free exists in the Zephyr second-generation work queue (kernel/work.c) in the handling of delayable work timeouts. When a delayable work item's timeout has been … | Aug 14, 2026 |
| CVE-2026-12364 | HIGH | 8.4 | The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was a pure pass-through: it forwarded the caller-supplied source, desc, package, and data arguments directly to the kernel-mode … | Aug 14, 2026 |
| CVE-2026-12363 | MEDIUM | 4.2 | The LoRaWAN Fragmented Data Block Transport service (subsys/lorawan/services/frag_transport.c) does not validate the fragment counter in a received DATA_FRAGMENT command before forwarding it to the configured … | Aug 14, 2026 |
| CVE-2026-73846 | MEDIUM | 6.5 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request parameters with unescaped ampersand, equals-sign, … | Aug 14, 2026 |
| CVE-2026-73845 | MEDIUM | 5.3 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaServer to … | Aug 14, 2026 |
| CVE-2026-73844 | LOW | 3.7 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception … | Aug 14, 2026 |
| CVE-2026-73107 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 14, 2026 |
| CVE-2026-49989 | UNKNOWN | — | CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they … | Aug 14, 2026 |
| CVE-2026-49986 | UNKNOWN | — | The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code … | Aug 14, 2026 |