Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48891
Total
3931
Critical
14494
High
14248
Medium
CVE ID Severity Score Description Published
CVE-2026-73068 MEDIUM 5.9 ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, the ToolJet Database HTTP … Aug 11, 2026
CVE-2026-6727 UNKNOWN A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able … Aug 11, 2026
CVE-2026-6726 UNKNOWN An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a … Aug 11, 2026
CVE-2026-67180 HIGH 8.4 Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code … Aug 11, 2026
CVE-2026-67179 HIGH 7.8 Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach … Aug 11, 2026
CVE-2026-56721 HIGH 8.8 CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authenticated low-privileged attackers to overwrite any user's … Aug 11, 2026
CVE-2026-56720 MEDIUM 4.3 CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that allows any authenticated user to access any other user's … Aug 11, 2026
CVE-2026-53416 HIGH 7.1 Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access. Aug 11, 2026
CVE-2026-53415 HIGH 8.3 Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network … Aug 11, 2026
CVE-2026-53414 MEDIUM 6.5 Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service … Aug 11, 2026
CVE-2026-53413 HIGH 8.3 Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of … Aug 11, 2026
CVE-2026-48766 HIGH 7.6 TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to exfiltrate stored OpenAI-compatible API keys by … Aug 11, 2026
CVE-2026-48495 HIGH 7.1 TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JSON `state` parameter and trusts the embedded … Aug 11, 2026
CVE-2026-42142 HIGH 7.1 TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getSheets`) does not validate workspace membership, allowing any authenticated user … Aug 11, 2026
CVE-2026-19546 HIGH 8.8 A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, … Aug 11, 2026
CVE-2026-19078 MEDIUM 4.3 A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly … Aug 11, 2026
CVE-2026-18640 HIGH 7.1 The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org's data … Aug 11, 2026
CVE-2026-18639 HIGH 7.3 When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to … Aug 11, 2026
CVE-2026-18638 MEDIUM 6.5 Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single request, by calling SetPassword … Aug 11, 2026
CVE-2026-14180 MEDIUM 5.3 A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer … Aug 11, 2026
CVE-2026-11814 UNKNOWN A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to … Aug 11, 2026
CVE-2026-11739 UNKNOWN A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker … Aug 11, 2026
CVE-2026-11738 UNKNOWN Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and … Aug 11, 2026
CVE-2026-11737 UNKNOWN Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software … Aug 11, 2026
CVE-2026-11736 UNKNOWN A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality. Aug 11, 2026