Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47944
Total
3850
Critical
14243
High
13921
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-73532 | CRITICAL | 9.8 | Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build … | Aug 13, 2026 |
| CVE-2026-73515 | HIGH | 8.1 | PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. … | Aug 13, 2026 |
| CVE-2026-73514 | HIGH | 8.8 | The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to … | Aug 13, 2026 |
| CVE-2026-55401 | UNKNOWN | — | CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet to a … | Aug 13, 2026 |
| CVE-2026-55400 | UNKNOWN | — | CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated session can send specially crafted traffic to a … | Aug 13, 2026 |
| CVE-2026-19744 | UNKNOWN | — | Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the application origin via a Markdown … | Aug 13, 2026 |
| CVE-2026-19710 | HIGH | 7.3 | A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file app/admin/departments/view_department.php. Performing a manipulation … | Aug 13, 2026 |
| CVE-2026-19487 | MEDIUM | 5.3 | Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass. The … | Aug 13, 2026 |
| CVE-2026-73558 | MEDIUM | 5.3 | vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x * 2 * d in activation_kernels.cu … | Aug 13, 2026 |
| CVE-2026-73557 | UNKNOWN | — | vLLM is an inference and serving engine for large language models. From 0.20.2rc0 until 0.26.0, safe_load_prompt_embeds in vllm/renderers/embed_utils.py uses torch.sparse.check_sparse_tensor_invariants, whose process-global save, enable, and … | Aug 13, 2026 |
| CVE-2026-73556 | MEDIUM | 5.3 | vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_format_enforcer.py is passed to lmformatenforcer.RegexParser without compile_regex_with_timeout … | Aug 13, 2026 |
| CVE-2026-73555 | MEDIUM | 5.3 | vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts FastAPI RequestValidationError objects with str(exc), and … | Aug 13, 2026 |
| CVE-2026-73509 | HIGH | 7.6 | OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by … | Aug 13, 2026 |
| CVE-2026-73508 | MEDIUM | 5.3 | Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDnsRecord, io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord(), and io.netty.handler.codec.dns.DnsCodecUtil.decompressDomainName() failed to release retained or newly allocated ByteBuf … | Aug 13, 2026 |
| CVE-2026-73507 | HIGH | 7.5 | Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to preserve closing-tag parser state across invocations, so an unauthenticated … | Aug 13, 2026 |
| CVE-2026-73506 | MEDIUM | 6.1 | Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune) in src/terminal/writer.go emitted attacker-controlled current directory names … | Aug 13, 2026 |
| CVE-2026-73505 | HIGH | 7.8 | Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes … | Aug 13, 2026 |
| CVE-2026-70464 | HIGH | 7.5 | rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake … | Aug 13, 2026 |
| CVE-2026-70463 | HIGH | 8.1 | rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, … | Aug 13, 2026 |
| CVE-2026-70462 | MEDIUM | 6.5 | rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disable connection timeouts by injecting … | Aug 13, 2026 |
| CVE-2026-70461 | HIGH | 8.2 | rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a … | Aug 13, 2026 |
| CVE-2026-70460 | HIGH | 8.1 | rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module … | Aug 13, 2026 |
| CVE-2026-70459 | MEDIUM | 5.3 | rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daemon by sending … | Aug 13, 2026 |
| CVE-2026-70458 | HIGH | 8.2 | rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED … | Aug 13, 2026 |
| CVE-2026-70457 | MEDIUM | 6.5 | rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is used directly as an index into a .bss-segment … | Aug 13, 2026 |