Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48624
Total
3905
Critical
14425
High
14119
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-73567 | CRITICAL | 9.1 | sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.generateKeyPairHex() path in Node.js uses the … | Aug 13, 2026 |
| CVE-2026-73566 | HIGH | 7.5 | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive … | Aug 13, 2026 |
| CVE-2026-73565 | MEDIUM | 5.3 | @hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request to an upgradeWebSocket route with a missing or malformed … | Aug 13, 2026 |
| CVE-2026-73564 | UNKNOWN | — | frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH exec channel request by adding … | Aug 13, 2026 |
| CVE-2026-73563 | MEDIUM | 4.7 | Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registration and client ID metadata document features in the … | Aug 13, 2026 |
| CVE-2026-73562 | MEDIUM | 6.5 | Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update … | Aug 13, 2026 |
| CVE-2026-73561 | HIGH | 7.5 | Hub is a Node.js WebSocket server and client with added features. Prior to 0.2.16, every incoming unauthenticated WebSocket connection triggers loadDefaultConnectionEventListeners to call requestClientId, which … | Aug 13, 2026 |
| CVE-2026-72741 | HIGH | 8.1 | Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another … | Aug 13, 2026 |
| CVE-2026-67614 | CRITICAL | 9.8 | CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens … | Aug 13, 2026 |
| CVE-2026-67613 | MEDIUM | 4.9 | CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths … | Aug 13, 2026 |
| CVE-2026-19730 | MEDIUM | 4.2 | The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on … | Aug 13, 2026 |
| CVE-2026-18428 | HIGH | 8.8 | A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access … | Aug 13, 2026 |
| CVE-2026-12908 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this … | Aug 13, 2026 |
| CVE-2026-12236 | MEDIUM | 6.5 | The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By Type Response received from a remote GATT server during BT_GATT_DISCOVER_STD_CHAR_DESC discovery. … | Aug 13, 2026 |
| CVE-2024-58374 | HIGH | 7.5 | Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a … | Aug 13, 2026 |
| CVE-2019-25765 | HIGH | 7.5 | ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in … | Aug 13, 2026 |
| CVE-2026-73266 | HIGH | 7.1 | A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows … | Aug 13, 2026 |
| CVE-2026-59765 | UNKNOWN | — | SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata | Aug 13, 2026 |
| CVE-2026-59763 | MEDIUM | 4.3 | Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads | Aug 13, 2026 |
| CVE-2026-59109 | HIGH | 8.8 | SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, … | Aug 13, 2026 |
| CVE-2026-58511 | LOW | 2.7 | Webhook Authorization Header Returned in Plaintext via API | Aug 13, 2026 |
| CVE-2026-58510 | MEDIUM | 4.3 | GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private | Aug 13, 2026 |
| CVE-2026-58508 | UNKNOWN | — | Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) | Aug 13, 2026 |
| CVE-2026-58507 | UNKNOWN | — | Private Repository Existence Disclosure via go-get Meta Endpoint | Aug 13, 2026 |
| CVE-2026-58445 | UNKNOWN | — | Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API | Aug 13, 2026 |