Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

29232
Total
2268
Critical
8711
High
9096
Medium
CVE ID Severity Score Description Published
CVE-2026-8612 MEDIUM 5.3 WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response forgery and code execution. With no explicit … May 15, 2026
CVE-2026-0438 UNKNOWN A System Management Mode (SMM) handler could perform a callout to code located in non-SMM/untrusted memory. A highly privileged attacker could, with active user interaction … May 15, 2026
CVE-2026-0432 UNKNOWN Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalation resulting in arbitrary code execution. May 15, 2026
CVE-2025-52540 UNKNOWN An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local attacker to write Out-of-Bounds, potentially resulting in privilege … May 15, 2026
CVE-2025-48521 UNKNOWN Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-After-Free (UAF) condition, potentially resulting in … May 15, 2026
CVE-2025-48520 UNKNOWN An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read Out-of-Bounds potentially resulting in information … May 15, 2026
CVE-2025-48519 UNKNOWN An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read or write Out-of-Bounds, potentially resulting … May 15, 2026
CVE-2025-48512 UNKNOWN Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) could allow an attacker to achieve privilege escalation resulting in arbitrary … May 15, 2026
CVE-2025-0045 UNKNOWN Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer overflow condition, potentially resulting in … May 15, 2026
CVE-2024-36345 UNKNOWN Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an out-of-bounds read, potentially resulting … May 15, 2026
CVE-2026-6811 MEDIUM 5.9 Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of … May 14, 2026
CVE-2026-45248 MEDIUM 5.3 Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users endpoint that allows unauthenticated attackers to retrieve sensitive user information. Attackers can … May 14, 2026
CVE-2026-44671 HIGH 7.5 ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerability was discovered in Zitadel's LDAP identity provider implementation, … May 14, 2026
CVE-2026-44428 UNKNOWN The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.6, the client-side and … May 14, 2026
CVE-2026-44427 UNKNOWN The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. From 1.1.0 to 1.7.4, the TrailingSlashMiddleware … May 14, 2026
CVE-2026-45781 LOW 3.5 The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.9, OCI ownership validation … May 14, 2026
CVE-2026-45370 HIGH 7.7 python-utcp is the python implementation of UTCP. Prior to 1.1.3, _prepare_environment() in cli_communication_protocol.py passes a full copy of os.environ to every CLI subprocess. When combined … May 14, 2026
CVE-2026-45369 HIGH 8.3 python-utcp is the python implementation of UTCP. Prior to 1.1.3, the _substitute_utcp_args method in cli_communication_protocol.py inserts user-controlled tool_args values directly into shell command strings without … May 14, 2026
CVE-2026-44700 UNKNOWN Elixir WebRTC is an Elixir implementation of the W3C WebRTC API. Prior to 0.15.1 and 0.16.1, missing DTLS peer certificate fingerprint validation in the DTLS … May 14, 2026
CVE-2026-44679 UNKNOWN Tuist is a virtual platform team for Swift app devs. Prior to 1.180.10, the forgot password flow allows an unauthenticated attacker to repeatedly trigger password … May 14, 2026
CVE-2026-44678 UNKNOWN Tuist is a virtual platform team for Swift app devs. In 1.180.8 and earlier, the DELETE /api/projects/{account_handle}/{project_handle}/previews/{preview_id} endpoint loads the preview by its UUID without … May 14, 2026
CVE-2026-44673 HIGH 7.5 libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer … May 14, 2026
CVE-2026-44666 UNKNOWN HRConvert2 is a self-hosted, drag-and-drop & nosql file conversion server & share tool. Prior to 3.3.8, the sanitizeString() function in convertCore.php is missing backtick (`) … May 14, 2026
CVE-2026-44662 UNKNOWN rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.0 to before 0.10.79, CipherCtxRef::cipher_update, CipherCtxRef::cipher_update_vec, and symm::Crypter::update incorrectly sized output buffers when used with … May 14, 2026
CVE-2026-44661 MEDIUM 4.7 python-utcp is the python implementation of UTCP. Prior to 1.1.3, the utcp-http plugin is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a … May 14, 2026