Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48678
Total
3911
Critical
14443
High
14141
Medium
CVE ID Severity Score Description Published
CVE-2026-49819 CRITICAL 9.8 UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as … Aug 13, 2026
CVE-2026-49473 HIGH 8.8 @cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before … Aug 13, 2026
CVE-2026-48791 LOW 2.0 sigstore-java is a sigstore java client for interacting with sigstore infrastructure. Version 2.0.0 erroneously removed verification of the integrated (Rekor entry) time) against the Fulcio … Aug 13, 2026
CVE-2026-46688 UNKNOWN The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, an unauthenticated request can be made to … Aug 13, 2026
CVE-2026-46382 UNKNOWN The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local URI can be made … Aug 13, 2026
CVE-2026-17431 MEDIUM 6.1 PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in … Aug 13, 2026
CVE-2026-16770 CRITICAL 9.8 PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file source, … Aug 13, 2026
CVE-2026-71194 MEDIUM 6.8 In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name … Aug 12, 2026
CVE-2026-71193 CRITICAL 9.6 In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user … Aug 12, 2026
CVE-2026-49481 CRITICAL 9.6 UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due … Aug 12, 2026
CVE-2026-47718 UNKNOWN FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and scheduler APIs. … Aug 12, 2026
CVE-2026-47717 HIGH 7.5 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even … Aug 12, 2026
CVE-2026-15424 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 12, 2026
CVE-2026-15141 UNKNOWN The web interface of the affected device relies on the HTTP referrer header as part of request validation. Requests containing empty Referer value, or omitting … Aug 12, 2026
CVE-2026-7366 MEDIUM 4.2 IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that … Aug 12, 2026
CVE-2026-73519 CRITICAL 9.8 WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass … Aug 12, 2026
CVE-2026-73501 CRITICAL 9.1 kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil … Aug 12, 2026
CVE-2026-73500 UNKNOWN etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can … Aug 12, 2026
CVE-2026-73499 UNKNOWN etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission … Aug 12, 2026
CVE-2026-73498 HIGH 7.7 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to … Aug 12, 2026
CVE-2026-73495 HIGH 7.4 blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42, blaze-server can merge HTTP/1.1 chunked-body … Aug 12, 2026
CVE-2026-73493 HIGH 7.5 Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with … Aug 12, 2026
CVE-2026-73492 UNKNOWN Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not … Aug 12, 2026
CVE-2026-71846 MEDIUM 6.5 A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code … Aug 12, 2026
CVE-2026-71473 HIGH 8.5 A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them … Aug 12, 2026