Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
29232
Total
2268
Critical
8711
High
9096
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-8612 | MEDIUM | 5.3 | WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response forgery and code execution. With no explicit … | May 15, 2026 |
| CVE-2026-0438 | UNKNOWN | — | A System Management Mode (SMM) handler could perform a callout to code located in non-SMM/untrusted memory. A highly privileged attacker could, with active user interaction … | May 15, 2026 |
| CVE-2026-0432 | UNKNOWN | — | Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalation resulting in arbitrary code execution. | May 15, 2026 |
| CVE-2025-52540 | UNKNOWN | — | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local attacker to write Out-of-Bounds, potentially resulting in privilege … | May 15, 2026 |
| CVE-2025-48521 | UNKNOWN | — | Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-After-Free (UAF) condition, potentially resulting in … | May 15, 2026 |
| CVE-2025-48520 | UNKNOWN | — | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read Out-of-Bounds potentially resulting in information … | May 15, 2026 |
| CVE-2025-48519 | UNKNOWN | — | An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read or write Out-of-Bounds, potentially resulting … | May 15, 2026 |
| CVE-2025-48512 | UNKNOWN | — | Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) could allow an attacker to achieve privilege escalation resulting in arbitrary … | May 15, 2026 |
| CVE-2025-0045 | UNKNOWN | — | Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer overflow condition, potentially resulting in … | May 15, 2026 |
| CVE-2024-36345 | UNKNOWN | — | Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an out-of-bounds read, potentially resulting … | May 15, 2026 |
| CVE-2026-6811 | MEDIUM | 5.9 | Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of … | May 14, 2026 |
| CVE-2026-45248 | MEDIUM | 5.3 | Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users endpoint that allows unauthenticated attackers to retrieve sensitive user information. Attackers can … | May 14, 2026 |
| CVE-2026-44671 | HIGH | 7.5 | ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerability was discovered in Zitadel's LDAP identity provider implementation, … | May 14, 2026 |
| CVE-2026-44428 | UNKNOWN | — | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.6, the client-side and … | May 14, 2026 |
| CVE-2026-44427 | UNKNOWN | — | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. From 1.1.0 to 1.7.4, the TrailingSlashMiddleware … | May 14, 2026 |
| CVE-2026-45781 | LOW | 3.5 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.9, OCI ownership validation … | May 14, 2026 |
| CVE-2026-45370 | HIGH | 7.7 | python-utcp is the python implementation of UTCP. Prior to 1.1.3, _prepare_environment() in cli_communication_protocol.py passes a full copy of os.environ to every CLI subprocess. When combined … | May 14, 2026 |
| CVE-2026-45369 | HIGH | 8.3 | python-utcp is the python implementation of UTCP. Prior to 1.1.3, the _substitute_utcp_args method in cli_communication_protocol.py inserts user-controlled tool_args values directly into shell command strings without … | May 14, 2026 |
| CVE-2026-44700 | UNKNOWN | — | Elixir WebRTC is an Elixir implementation of the W3C WebRTC API. Prior to 0.15.1 and 0.16.1, missing DTLS peer certificate fingerprint validation in the DTLS … | May 14, 2026 |
| CVE-2026-44679 | UNKNOWN | — | Tuist is a virtual platform team for Swift app devs. Prior to 1.180.10, the forgot password flow allows an unauthenticated attacker to repeatedly trigger password … | May 14, 2026 |
| CVE-2026-44678 | UNKNOWN | — | Tuist is a virtual platform team for Swift app devs. In 1.180.8 and earlier, the DELETE /api/projects/{account_handle}/{project_handle}/previews/{preview_id} endpoint loads the preview by its UUID without … | May 14, 2026 |
| CVE-2026-44673 | HIGH | 7.5 | libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer … | May 14, 2026 |
| CVE-2026-44666 | UNKNOWN | — | HRConvert2 is a self-hosted, drag-and-drop & nosql file conversion server & share tool. Prior to 3.3.8, the sanitizeString() function in convertCore.php is missing backtick (`) … | May 14, 2026 |
| CVE-2026-44662 | UNKNOWN | — | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.0 to before 0.10.79, CipherCtxRef::cipher_update, CipherCtxRef::cipher_update_vec, and symm::Crypter::update incorrectly sized output buffers when used with … | May 14, 2026 |
| CVE-2026-44661 | MEDIUM | 4.7 | python-utcp is the python implementation of UTCP. Prior to 1.1.3, the utcp-http plugin is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a … | May 14, 2026 |