Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48891
Total
3931
Critical
14494
High
14248
Medium
CVE ID Severity Score Description Published
CVE-2026-13738 UNKNOWN CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, … Aug 11, 2026
CVE-2026-13737 UNKNOWN CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command … Aug 11, 2026
CVE-2026-58231 CRITICAL 10.0 SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful … Aug 11, 2026
CVE-2026-73162 UNKNOWN Affected versions of MISP cti-transmute expose several state-changing account operations as GET requests: * /account/follow * /account/delete_notification * /account/mark_notification_read * /account/mark_all_read These endpoints require authentication, … Aug 11, 2026
CVE-2026-33922 MEDIUM 6.0 A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an input parameter. A … Aug 11, 2026
CVE-2026-33921 MEDIUM 5.2 The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of … Aug 11, 2026
CVE-2026-73161 UNKNOWN Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feature. The highlight() function previously returned the underlying text directly when no … Aug 11, 2026
CVE-2026-73160 UNKNOWN Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints. The URL validation routine checked whether a supplied hostname was itself … Aug 11, 2026
CVE-2026-73159 UNKNOWN Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's v-html. The helper mapIcon() previously constructed … Aug 11, 2026
CVE-2026-73158 UNKNOWN Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can contain style properties that are later consumed by Pivotick, and Pivotick interprets … Aug 11, 2026
CVE-2026-73157 UNKNOWN Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface using HTML interpolation. Because fields such as event IDs, … Aug 11, 2026
CVE-2026-72694 HIGH 7.1 A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can … Aug 11, 2026
CVE-2026-72693 HIGH 7.8 `openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the … Aug 11, 2026
CVE-2026-71218 MEDIUM 5.3 A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and … Aug 11, 2026
CVE-2026-71217 HIGH 7.5 A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` … Aug 11, 2026
CVE-2026-15567 HIGH 7.5 A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds … Aug 11, 2026
CVE-2026-15565 HIGH 7.5 A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has … Aug 11, 2026
CVE-2026-15563 HIGH 7.4 A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding … Aug 11, 2026
CVE-2026-15562 HIGH 7.5 A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake … Aug 11, 2026
CVE-2026-15561 HIGH 7.5 A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection … Aug 11, 2026
CVE-2026-15560 HIGH 8.1 when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and … Aug 11, 2026
CVE-2026-15556 HIGH 8.1 A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to … Aug 11, 2026
CVE-2026-15555 HIGH 8.8 A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class … Aug 11, 2026
CVE-2026-15554 HIGH 7.4 the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access … Aug 11, 2026
CVE-2026-10579 CRITICAL 9.8 A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker … Aug 11, 2026