Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47944
Total
3850
Critical
14243
High
13921
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-53798 | MEDIUM | 5.3 | rsync tbefore 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that allows local attackers to cause transferred files to be owned … | Aug 13, 2026 |
| CVE-2026-53797 | MEDIUM | 4.7 | rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's source tree traversal that allows an attacker who can manipulate a parent directory … | Aug 13, 2026 |
| CVE-2026-53796 | MEDIUM | 6.3 | rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver's destination directory handling that allows an attacker who can … | Aug 13, 2026 |
| CVE-2026-53795 | HIGH | 8.1 | rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by specifying an absolute path … | Aug 13, 2026 |
| CVE-2026-53794 | MEDIUM | 5.3 | rsync before 3.5.0 contains a logic error in --max-alloc handling that allows a sender or configuration setting --max-alloc=0 to disable allocation sanity checks entirely rather … | Aug 13, 2026 |
| CVE-2026-53793 | HIGH | 7.4 | rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement by constructing paths that resolve … | Aug 13, 2026 |
| CVE-2026-53792 | MEDIUM | 6.5 | rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a malicious receiver to trigger memory access before the … | Aug 13, 2026 |
| CVE-2026-53791 | CRITICAL | 9.1 | rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY … | Aug 13, 2026 |
| CVE-2026-53790 | HIGH | 8.1 | rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, … | Aug 13, 2026 |
| CVE-2026-53789 | MEDIUM | 6.5 | rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destination … | Aug 13, 2026 |
| CVE-2026-53788 | MEDIUM | 6.5 | rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allows local attackers to forge protocol messages by creating user … | Aug 13, 2026 |
| CVE-2026-53786 | MEDIUM | 6.5 | rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-level filter restrictions by supplying malicious --filter merge file directives. … | Aug 13, 2026 |
| CVE-2026-53785 | HIGH | 7.1 | rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory tree by crafting relative … | Aug 13, 2026 |
| CVE-2026-53784 | HIGH | 7.1 | rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled … | Aug 13, 2026 |
| CVE-2026-53783 | HIGH | 8.1 | rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced … | Aug 13, 2026 |
| CVE-2026-49857 | HIGH | 7.4 | auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages. Version 3.0.1 implements SSRF protection in `assertSafeUrl()` (`src/security.ts`) to block … | Aug 13, 2026 |
| CVE-2026-49856 | MEDIUM | 4.3 | @jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research. In version 0.3.1, he network domain has a central … | Aug 13, 2026 |
| CVE-2026-49820 | MEDIUM | 4.7 | Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo's `saferedirect` package validates redirect URLs used across authentication … | Aug 13, 2026 |
| CVE-2026-28154 | HIGH | 7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - … | Aug 13, 2026 |
| CVE-2026-19734 | UNKNOWN | — | Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus Prospero Flow CRM before 5.4.7 allows authenticated users of any … | Aug 13, 2026 |
| CVE-2026-19293 | HIGH | 8.8 | SMP security request (from peripheral) does not include the maximum encryption key size supported. Using a key with less than the maximum keysize makes brute-forcing … | Aug 13, 2026 |
| CVE-2026-19292 | HIGH | 8.8 | Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked … | Aug 13, 2026 |
| CVE-2026-19291 | HIGH | 8.8 | Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below. | Aug 13, 2026 |
| CVE-2026-16101 | HIGH | 8.8 | Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below | Aug 13, 2026 |
| CVE-2026-15994 | HIGH | 7.0 | During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated … | Aug 13, 2026 |