Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48891
Total
3931
Critical
14494
High
14248
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-73156 | UNKNOWN | — | Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap tooltip formatters. Slice names may originate directly from STIX or … | Aug 11, 2026 |
| CVE-2026-73155 | UNKNOWN | — | Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first checking whether those users are authorized to view … | Aug 11, 2026 |
| CVE-2026-73140 | UNKNOWN | — | Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report exports. Although normal comment retrieval filters comments according to conversion visibility, … | Aug 11, 2026 |
| CVE-2026-19519 | MEDIUM | 4.3 | A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked type assertion to panic … | Aug 11, 2026 |
| CVE-2026-19418 | UNKNOWN | — | The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the … | Aug 11, 2026 |
| CVE-2026-19518 | MEDIUM | 6.5 | Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation. | Aug 11, 2026 |
| CVE-2026-19517 | MEDIUM | 6.5 | Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlottie allows Excessive Allocation. | Aug 11, 2026 |
| CVE-2026-19391 | MEDIUM | 6.5 | A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD … | Aug 11, 2026 |
| CVE-2026-16053 | HIGH | 8.5 | Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module. | Aug 11, 2026 |
| CVE-2026-8158 | MEDIUM | 5.3 | The Signed Video Framework contained a buffer overflow issue which could lead the application using this framework to crash. The issue exclusively affects the tools … | Aug 11, 2026 |
| CVE-2026-6505 | MEDIUM | 5.1 | The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if … | Aug 11, 2026 |
| CVE-2026-6181 | MEDIUM | 5.9 | The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer-privileged service account. | Aug 11, 2026 |
| CVE-2026-5304 | MEDIUM | 5.7 | An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is … | Aug 11, 2026 |
| CVE-2026-5303 | MEDIUM | 5.7 | The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if … | Aug 11, 2026 |
| CVE-2026-4757 | HIGH | 7.2 | A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can only be … | Aug 11, 2026 |
| CVE-2026-19516 | CRITICAL | 9.1 | A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, … | Aug 11, 2026 |
| CVE-2026-18348 | MEDIUM | 4.1 | Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor … | Aug 11, 2026 |
| CVE-2026-14549 | UNKNOWN | — | The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated … | Aug 11, 2026 |
| CVE-2026-14548 | UNKNOWN | — | The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated … | Aug 11, 2026 |
| CVE-2026-13716 | CRITICAL | 9.1 | Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to … | Aug 11, 2026 |
| CVE-2026-12052 | MEDIUM | 5.2 | The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next/class/usbd_cdc_ncm.c builds a fixed-size response for the GET_NTB_PARAMETERS (28-byte struct ntb_parameters) and GET_NTB_INPUT_SIZE (8-byte struct … | Aug 11, 2026 |
| CVE-2026-12051 | MEDIUM | 4.6 | The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer dereference in handle_download() (subsys/usb/device_next/class/usbd_dfu.c). The handler computes MIN(setup->wLength, … | Aug 11, 2026 |
| CVE-2026-11894 | MEDIUM | 5.9 | The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the bt_hci_driver_api buffer-ownership contract. That contract requires the driver to consume (unref) the … | Aug 11, 2026 |
| CVE-2026-19425 | CRITICAL | 9.8 | Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, … | Aug 11, 2026 |
| CVE-2026-16974 | MEDIUM | 6.4 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post_meta Shortcode in all … | Aug 11, 2026 |