Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48124
Total
3850
Critical
14244
High
13921
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-18749 | CRITICAL | 9.8 | The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been marked shared is still retrievable by … | Aug 12, 2026 |
| CVE-2026-18744 | MEDIUM | 6.5 | Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func only checks _is_my_case, not ownership … | Aug 12, 2026 |
| CVE-2026-18727 | MEDIUM | 6.5 | A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) … | Aug 12, 2026 |
| CVE-2026-18726 | MEDIUM | 6.5 | A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) … | Aug 12, 2026 |
| CVE-2026-17485 | HIGH | 8.2 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an … | Aug 12, 2026 |
| CVE-2026-10534 | HIGH | 8.4 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser. | Aug 12, 2026 |
| CVE-2024-27253 | CRITICAL | 10.0 | IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities. | Aug 12, 2026 |
| CVE-2026-73491 | UNKNOWN | — | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not … | Aug 12, 2026 |
| CVE-2026-73490 | MEDIUM | 4.7 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies … | Aug 12, 2026 |
| CVE-2026-73430 | MEDIUM | 5.3 | Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can cause a denial of service by sending SSH_MSG_KEX_ECDH_INIT … | Aug 12, 2026 |
| CVE-2026-73429 | MEDIUM | 5.3 | Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session with a malformed … | Aug 12, 2026 |
| CVE-2026-73427 | UNKNOWN | — | Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cross-site scripting when a crafted application/x-trix-document JSON payload … | Aug 12, 2026 |
| CVE-2026-73425 | LOW | 3.7 | Astro is a web framework for content-driven websites. Prior to 8.1.2, the Astro Netlify adapter converts each image.remotePatterns entry into a regular expression written to … | Aug 12, 2026 |
| CVE-2026-73423 | UNKNOWN | — | Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/hono pipeline installs security.checkOrigin only through the middleware() primitive, while actions() … | Aug 12, 2026 |
| CVE-2026-73422 | UNKNOWN | — | Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS generator interpolates animation properties into an inline style … | Aug 12, 2026 |
| CVE-2026-73419 | MEDIUM | 6.8 | NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier … | Aug 12, 2026 |
| CVE-2026-73418 | HIGH | 7.5 | NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can … | Aug 12, 2026 |
| CVE-2026-66898 | CRITICAL | 9.9 | A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a … | Aug 12, 2026 |
| CVE-2026-65370 | HIGH | 7.5 | ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. This vulnerability is addressed in servicetalk version 0.42.65. | Aug 12, 2026 |
| CVE-2026-64826 | MEDIUM | 6.5 | rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized directory traversal sequences in the filename … | Aug 12, 2026 |
| CVE-2026-62421 | UNKNOWN | — | Rejected reason: Voluntarily withdrawn | Aug 12, 2026 |
| CVE-2026-19654 | HIGH | 7.5 | A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery … | Aug 12, 2026 |
| CVE-2026-19503 | MEDIUM | 4.8 | MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's … | Aug 12, 2026 |
| CVE-2026-19502 | MEDIUM | 5.5 | MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain … | Aug 12, 2026 |
| CVE-2026-19130 | MEDIUM | 5.8 | A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior … | Aug 12, 2026 |