Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48124
Total
3850
Critical
14244
High
13921
Medium
CVE ID Severity Score Description Published
CVE-2026-46382 UNKNOWN The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local URI can be made … Aug 13, 2026
CVE-2026-17431 MEDIUM 6.1 PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in … Aug 13, 2026
CVE-2026-16770 CRITICAL 9.8 PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file source, … Aug 13, 2026
CVE-2026-71194 MEDIUM 6.8 In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name … Aug 12, 2026
CVE-2026-71193 CRITICAL 9.6 In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user … Aug 12, 2026
CVE-2026-49481 CRITICAL 9.6 UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due … Aug 12, 2026
CVE-2026-47718 UNKNOWN FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and scheduler APIs. … Aug 12, 2026
CVE-2026-47717 HIGH 7.5 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even … Aug 12, 2026
CVE-2026-15424 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 12, 2026
CVE-2026-15141 UNKNOWN The web interface of the affected device relies on the HTTP referrer header as part of request validation. Requests containing empty Referer value, or omitting … Aug 12, 2026
CVE-2026-7366 MEDIUM 4.2 IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that … Aug 12, 2026
CVE-2026-73519 CRITICAL 9.8 WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass … Aug 12, 2026
CVE-2026-73501 CRITICAL 9.1 kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil … Aug 12, 2026
CVE-2026-73500 UNKNOWN etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can … Aug 12, 2026
CVE-2026-73499 UNKNOWN etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission … Aug 12, 2026
CVE-2026-73498 HIGH 7.7 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to … Aug 12, 2026
CVE-2026-73495 HIGH 7.4 blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42, blaze-server can merge HTTP/1.1 chunked-body … Aug 12, 2026
CVE-2026-73493 HIGH 7.5 Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with … Aug 12, 2026
CVE-2026-73492 UNKNOWN Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not … Aug 12, 2026
CVE-2026-71846 MEDIUM 6.5 A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code … Aug 12, 2026
CVE-2026-71473 HIGH 8.5 A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them … Aug 12, 2026
CVE-2026-71471 CRITICAL 9.0 A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), … Aug 12, 2026
CVE-2026-71469 HIGH 7.5 A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a … Aug 12, 2026
CVE-2026-19003 HIGH 7.8 A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds … Aug 12, 2026
CVE-2026-18750 MEDIUM 5.3 vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belongs to the requesting group-admin. Lets … Aug 12, 2026