Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48747
Total
3915
Critical
14448
High
14180
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-59916 | HIGH | 7.8 | Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially … | Aug 12, 2026 |
| CVE-2026-59914 | HIGH | 7.8 | Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access … | Aug 12, 2026 |
| CVE-2026-4879 | MEDIUM | 4.3 | GitLab has remediated an issue in GitLab EE affecting all versions from 16.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain … | Aug 12, 2026 |
| CVE-2026-49466 | MEDIUM | 6.5 | Draft List is a WordPress plugin to manage and promote unpublished content. Versions 2.6.3 and below are vulnerable to stored Cross-Site Scripting (XSS) in the … | Aug 12, 2026 |
| CVE-2026-46731 | HIGH | 7.8 | Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access … | Aug 12, 2026 |
| CVE-2026-19657 | MEDIUM | 6.1 | ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visiting a crafted URL can execute … | Aug 12, 2026 |
| CVE-2026-19656 | CRITICAL | 9.9 | ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating … | Aug 12, 2026 |
| CVE-2026-19643 | MEDIUM | 5.3 | An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow a remote authenticated user to crash an … | Aug 12, 2026 |
| CVE-2026-19642 | MEDIUM | 5.9 | An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authenticated user to cause a crash or heap … | Aug 12, 2026 |
| CVE-2026-19228 | HIGH | 8.5 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have … | Aug 12, 2026 |
| CVE-2026-18679 | UNKNOWN | — | When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer … | Aug 12, 2026 |
| CVE-2026-18433 | MEDIUM | 4.3 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have … | Aug 12, 2026 |
| CVE-2026-18150 | MEDIUM | 4.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition. | Aug 12, 2026 |
| CVE-2026-18148 | MEDIUM | 4.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to inject arbitrary content into Navigator log files due to improper output … | Aug 12, 2026 |
| CVE-2026-18099 | HIGH | 8.9 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to improper neutralization of user-controlled input. | Aug 12, 2026 |
| CVE-2026-17642 | HIGH | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used … | Aug 12, 2026 |
| CVE-2026-17445 | HIGH | 8.2 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of an attacker-supplied user … | Aug 12, 2026 |
| CVE-2026-17417 | HIGH | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of shell metacharacters. | Aug 12, 2026 |
| CVE-2026-17111 | HIGH | 7.6 | IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the … | Aug 12, 2026 |
| CVE-2026-17083 | CRITICAL | 9.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow. | Aug 12, 2026 |
| CVE-2026-17082 | HIGH | 8.8 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of a client-supplied profile … | Aug 12, 2026 |
| CVE-2026-16494 | HIGH | 7.1 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have … | Aug 12, 2026 |
| CVE-2026-15217 | HIGH | 8.7 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain … | Aug 12, 2026 |
| CVE-2026-15216 | HIGH | 8.7 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain … | Aug 12, 2026 |
| CVE-2026-13361 | HIGH | 8.8 | IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field. | Aug 12, 2026 |