Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48872
Total
3924
Critical
14491
High
14240
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-48386 | HIGH | 7.5 | ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability that could lead to disclosure of sensitive memory. An attacker could … | Aug 11, 2026 |
| CVE-2026-48385 | HIGH | 7.7 | ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in a Security … | Aug 11, 2026 |
| CVE-2026-48384 | MEDIUM | 4.9 | ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker with high privileges could exploit this vulnerability … | Aug 11, 2026 |
| CVE-2026-48376 | MEDIUM | 5.4 | is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this … | Aug 11, 2026 |
| CVE-2026-48375 | MEDIUM | 6.5 | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service. A low-privileged attacker could exploit this vulnerability to crash the … | Aug 11, 2026 |
| CVE-2026-48362 | CRITICAL | 10.0 | ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code … | Aug 11, 2026 |
| CVE-2026-47922 | MEDIUM | 4.7 | CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue requires user interaction … | Aug 11, 2026 |
| CVE-2026-47704 | UNKNOWN | — | TypeBot is a chatbot builder tool. Prior to version 3.17.0, an authenticated user who has read access to any typebot can resume a waiting webhook … | Aug 11, 2026 |
| CVE-2026-47299 | HIGH | 7.2 | Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network. | Aug 11, 2026 |
| CVE-2026-47285 | MEDIUM | 6.5 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | Aug 11, 2026 |
| CVE-2026-43606 | UNKNOWN | — | Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially perform timing analysis or electromagnetic emanation … | Aug 11, 2026 |
| CVE-2026-42976 | HIGH | 7.8 | Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally. | Aug 11, 2026 |
| CVE-2026-40375 | MEDIUM | 6.5 | Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network. | Aug 11, 2026 |
| CVE-2026-39452 | UNKNOWN | — | Protection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software … | Aug 11, 2026 |
| CVE-2026-35502 | UNKNOWN | — | Deserialization of untrusted data for some Intel(R) Extension for PyTorch before version 2.8.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged … | Aug 11, 2026 |
| CVE-2026-34635 | HIGH | 8.4 | is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability … | Aug 11, 2026 |
| CVE-2026-34175 | UNKNOWN | — | Uncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA before version 45cd723 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with … | Aug 11, 2026 |
| CVE-2026-32791 | UNKNOWN | — | Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version tag 202604 within Ring 3: User Applications may allow an escalation of … | Aug 11, 2026 |
| CVE-2026-32788 | UNKNOWN | — | Uncontrolled search path for some Approximate Bayesian Inference Framework before version on commit #484c949 within Ring 3: User Applications may allow an escalation of privilege. … | Aug 11, 2026 |
| CVE-2026-32677 | UNKNOWN | — | Path traversal for some gaudi-container-runtime before version 1.24.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated … | Aug 11, 2026 |
| CVE-2026-28757 | UNKNOWN | — | Protection mechanism failure for some Intel(R) Workload Services Framework software within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with … | Aug 11, 2026 |
| CVE-2026-28729 | UNKNOWN | — | Integer overflow in the UEFI firmware for the Intel(R) Slim Bootloader may allow an information disclosure. System software adversary with an authenticated user combined with … | Aug 11, 2026 |
| CVE-2026-28707 | UNKNOWN | — | Protection mechanism failure for some LLM-on-Ray before version 1.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a … | Aug 11, 2026 |
| CVE-2026-28700 | UNKNOWN | — | Uncontrolled search path for some EquiTriton before version f5ddbb5 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a … | Aug 11, 2026 |
| CVE-2026-27765 | UNKNOWN | — | Improper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R) software before version 0.16.0 within Ring 3: User Applications may allow a denial of … | Aug 11, 2026 |