Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49177
Total
3940
Critical
14579
High
14345
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-15972 | HIGH | 7.5 | Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC … | Aug 07, 2026 |
| CVE-2026-15970 | MEDIUM | 4.2 | Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a … | Aug 07, 2026 |
| CVE-2026-71852 | UNKNOWN | — | pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py … | Aug 07, 2026 |
| CVE-2026-71851 | CRITICAL | 9.0 | crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry … | Aug 07, 2026 |
| CVE-2026-71850 | MEDIUM | 4.8 | Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from hono/jsx retains the result of a … | Aug 07, 2026 |
| CVE-2026-71849 | LOW | 3.7 | Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy Helper proxy() function in hono/proxy does … | Aug 07, 2026 |
| CVE-2026-71848 | MEDIUM | 5.3 | Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the languageDetector middleware is vulnerable to algorithmic complexity … | Aug 07, 2026 |
| CVE-2026-71847 | UNKNOWN | — | Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input buffer but leaves … | Aug 07, 2026 |
| CVE-2026-70561 | MEDIUM | 6.5 | TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege guest accounts, to read arbitrary attachments by … | Aug 07, 2026 |
| CVE-2026-69127 | UNKNOWN | — | Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error … | Aug 07, 2026 |
| CVE-2026-66000 | UNKNOWN | — | Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation does not re-evaluate the recipient's current document permissions, allowing … | Aug 07, 2026 |
| CVE-2026-48098 | HIGH | 7.3 | NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 execute privileged … | Aug 07, 2026 |
| CVE-2026-48097 | HIGH | 7.8 | NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a … | Aug 07, 2026 |
| CVE-2026-19231 | HIGH | 7.3 | A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=delete_appointment. The manipulation of … | Aug 07, 2026 |
| CVE-2026-19230 | LOW | 3.5 | A vulnerability was identified in SourceCodester Photo Share Website 1.0. This affects an unknown part of the file /social/ajax.php?action=save_upload of the component Comment Input Box. … | Aug 07, 2026 |
| CVE-2026-17435 | UNKNOWN | — | File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files. When the file to be rotated is a symbolic link … | Aug 07, 2026 |
| CVE-2026-11430 | HIGH | 7.3 | Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook feature is enabled but no webhookToken is configured, a … | Aug 07, 2026 |
| CVE-2025-71413 | MEDIUM | 5.3 | Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets which may result in increased workload and reduced … | Aug 07, 2026 |
| CVE-2025-71412 | HIGH | 7.1 | Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper response actions by flight crews, traffic … | Aug 07, 2026 |
| CVE-2025-71411 | MEDIUM | 5.3 | Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out … | Aug 07, 2026 |
| CVE-2025-71410 | MEDIUM | 5.3 | Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and lead to a loss of CPDLC functions requiring … | Aug 07, 2026 |
| CVE-2025-71409 | HIGH | 7.1 | Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and … | Aug 07, 2026 |
| CVE-2025-63235 | HIGH | 7.5 | In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients send invalid CONNECT packets … | Aug 07, 2026 |
| CVE-2026-66058 | UNKNOWN | — | Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is possible for an authenticated … | Aug 07, 2026 |
| CVE-2026-64638 | UNKNOWN | — | WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it … | Aug 07, 2026 |