Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48891
Total
3931
Critical
14494
High
14248
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-73068 | MEDIUM | 5.9 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, the ToolJet Database HTTP … | Aug 11, 2026 |
| CVE-2026-6727 | UNKNOWN | — | A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able … | Aug 11, 2026 |
| CVE-2026-6726 | UNKNOWN | — | An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a … | Aug 11, 2026 |
| CVE-2026-67180 | HIGH | 8.4 | Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code … | Aug 11, 2026 |
| CVE-2026-67179 | HIGH | 7.8 | Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach … | Aug 11, 2026 |
| CVE-2026-56721 | HIGH | 8.8 | CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authenticated low-privileged attackers to overwrite any user's … | Aug 11, 2026 |
| CVE-2026-56720 | MEDIUM | 4.3 | CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that allows any authenticated user to access any other user's … | Aug 11, 2026 |
| CVE-2026-53416 | HIGH | 7.1 | Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access. | Aug 11, 2026 |
| CVE-2026-53415 | HIGH | 8.3 | Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network … | Aug 11, 2026 |
| CVE-2026-53414 | MEDIUM | 6.5 | Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service … | Aug 11, 2026 |
| CVE-2026-53413 | HIGH | 8.3 | Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of … | Aug 11, 2026 |
| CVE-2026-48766 | HIGH | 7.6 | TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to exfiltrate stored OpenAI-compatible API keys by … | Aug 11, 2026 |
| CVE-2026-48495 | HIGH | 7.1 | TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JSON `state` parameter and trusts the embedded … | Aug 11, 2026 |
| CVE-2026-42142 | HIGH | 7.1 | TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getSheets`) does not validate workspace membership, allowing any authenticated user … | Aug 11, 2026 |
| CVE-2026-19546 | HIGH | 8.8 | A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, … | Aug 11, 2026 |
| CVE-2026-19078 | MEDIUM | 4.3 | A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly … | Aug 11, 2026 |
| CVE-2026-18640 | HIGH | 7.1 | The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org's data … | Aug 11, 2026 |
| CVE-2026-18639 | HIGH | 7.3 | When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to … | Aug 11, 2026 |
| CVE-2026-18638 | MEDIUM | 6.5 | Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single request, by calling SetPassword … | Aug 11, 2026 |
| CVE-2026-14180 | MEDIUM | 5.3 | A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer … | Aug 11, 2026 |
| CVE-2026-11814 | UNKNOWN | — | A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to … | Aug 11, 2026 |
| CVE-2026-11739 | UNKNOWN | — | A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker … | Aug 11, 2026 |
| CVE-2026-11738 | UNKNOWN | — | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and … | Aug 11, 2026 |
| CVE-2026-11737 | UNKNOWN | — | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software … | Aug 11, 2026 |
| CVE-2026-11736 | UNKNOWN | — | A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality. | Aug 11, 2026 |