Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48624
Total
3905
Critical
14425
High
14119
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-14875 | HIGH | 7.3 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable … | Aug 13, 2026 |
| CVE-2026-14525 | CRITICAL | 9.4 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 … | Aug 13, 2026 |
| CVE-2026-13460 | HIGH | 7.5 | IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-node cluster … | Aug 13, 2026 |
| CVE-2026-13365 | HIGH | 7.1 | IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted … | Aug 13, 2026 |
| CVE-2026-10571 | MEDIUM | 5.7 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-privileged, administrative user could … | Aug 13, 2026 |
| CVE-2026-73653 | CRITICAL | 9.4 | Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, … | Aug 13, 2026 |
| CVE-2026-73652 | UNKNOWN | — | vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an ownership check, allowing one algorithm … | Aug 13, 2026 |
| CVE-2026-73651 | MEDIUM | 5.7 | TypeORM is a TypeScript and JavaScript ORM for Node.js that supports PostgreSQL, MySQL, MariaDB, SQLite, SQL Server, Oracle, and other databases. Prior to versions 0.3.31 … | Aug 13, 2026 |
| CVE-2026-73650 | HIGH | 8.2 | SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, … | Aug 13, 2026 |
| CVE-2026-73482 | HIGH | 8.1 | phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is triggered via an unauthenticated GET request (?page=admins&delete=N) that … | Aug 13, 2026 |
| CVE-2026-73481 | MEDIUM | 5.4 | phpList before 3.7.0-RC5 fail to enforce CSRF token validation on the bounce rule deletion endpoint (bouncerules.php / bouncerule.php). The deletion is performed via a GET … | Aug 13, 2026 |
| CVE-2026-73038 | MEDIUM | 6.1 | NodeBB before 4.15.0 contains a stored cross-site scripting vulnerability in the renderEmoji function that fails to escape tag.icon.url and tag.name attributes. Attackers can deliver malicious … | Aug 13, 2026 |
| CVE-2026-73037 | MEDIUM | 6.1 | Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without escaping into HTML and … | Aug 13, 2026 |
| CVE-2026-72777 | HIGH | 8.6 | Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns … | Aug 13, 2026 |
| CVE-2026-18071 | HIGH | 7.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper privilege management. | Aug 13, 2026 |
| CVE-2026-17220 | HIGH | 8.2 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a … | Aug 13, 2026 |
| CVE-2026-17197 | HIGH | 8.1 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity. | Aug 13, 2026 |
| CVE-2026-73649 | CRITICAL | 9.8 | Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only … | Aug 13, 2026 |
| CVE-2026-73648 | UNKNOWN | — | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used … | Aug 13, 2026 |
| CVE-2026-73647 | MEDIUM | 5.6 | Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/extend/extend.js recursively copied attacker-controlled object keys … | Aug 13, 2026 |
| CVE-2026-73645 | UNKNOWN | — | OpenZeppelin Confidential Contracts is an experimental library for developing applications on the Zama fhEVM. Prior to 0.3.1, the ERC7984 contract tracked confidential total supply with … | Aug 13, 2026 |
| CVE-2026-73644 | CRITICAL | 9.6 | OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not … | Aug 13, 2026 |
| CVE-2026-73643 | HIGH | 7.5 | js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2, parsing a small YAML document can take exponential time when an application calls … | Aug 13, 2026 |
| CVE-2026-73569 | UNKNOWN | — | fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until 5.10.1, src/xmlparser/OrderedObjParser.js processes multiple DOCTYPE declarations within … | Aug 13, 2026 |
| CVE-2026-73568 | HIGH | 7.5 | py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxer/yamux/yamux.py reads an attacker-controlled 32-bit DATA … | Aug 13, 2026 |