Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49645
Total
4014
Critical
14740
High
14481
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-64584 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: cancel pending IN work before freeing the midi object The f_midi driver … | Aug 06, 2026 |
| CVE-2026-64583 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown The Broadcom BDC UDC … | Aug 06, 2026 |
| CVE-2026-5430 | CRITICAL | 10.0 | The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with … | Aug 06, 2026 |
| CVE-2026-1728 | CRITICAL | 9.8 | Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability … | Aug 06, 2026 |
| CVE-2026-19021 | HIGH | 7.3 | A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by this issue is some unknown functionality of the file … | Aug 06, 2026 |
| CVE-2026-19020 | MEDIUM | 6.3 | A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /servicetype.php. This manipulation … | Aug 06, 2026 |
| CVE-2026-19019 | MEDIUM | 4.8 | A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_session_persistence of the file executor/app/core/workspace.py of the component Claude … | Aug 06, 2026 |
| CVE-2026-19011 | MEDIUM | 5.3 | A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function buildSystemPrompt of the file packages/server/src/routes/agents.ts. Performing a manipulation results in file inclusion. … | Aug 06, 2026 |
| CVE-2026-19010 | HIGH | 7.3 | A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packages/main/src/index.ts of the component Message API Endpoint. Such … | Aug 06, 2026 |
| CVE-2026-19009 | HIGH | 7.3 | A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core/src/response.ts of the component Message API Endpoint. This … | Aug 06, 2026 |
| CVE-2026-19008 | MEDIUM | 6.3 | A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape of the file src/agents/sandbox-paths.ts of the component apply_patch Tool. … | Aug 06, 2026 |
| CVE-2026-18915 | MEDIUM | 5.0 | Invocation of process using visible sensitive information vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute eta-otp-lock allows System Footprinting. This issue affects eta-otp-lock: before 1.0.4. | Aug 06, 2026 |
| CVE-2026-18649 | HIGH | 7.5 | A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the … | Aug 06, 2026 |
| CVE-2026-18597 | HIGH | 8.5 | The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could trigger an SSRF … | Aug 06, 2026 |
| CVE-2026-0637 | MEDIUM | 4.4 | When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization … | Aug 06, 2026 |
| CVE-2025-15039 | CRITICAL | 9.4 | The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators … | Aug 06, 2026 |
| CVE-2025-14779 | LOW | 3.8 | The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to … | Aug 06, 2026 |
| CVE-2025-13909 | MEDIUM | 4.3 | The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This … | Aug 06, 2026 |
| CVE-2025-13736 | LOW | 3.7 | When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays … | Aug 06, 2026 |
| CVE-2025-13394 | MEDIUM | 5.4 | The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET … | Aug 06, 2026 |
| CVE-2025-12627 | LOW | 2.4 | The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained … | Aug 06, 2026 |
| CVE-2025-11850 | MEDIUM | 4.3 | When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary user store and bypasses the primary user store during search and … | Aug 06, 2026 |
| CVE-2024-8995 | MEDIUM | 4.9 | Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, … | Aug 06, 2026 |
| CVE-2024-6832 | MEDIUM | 5.9 | The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if … | Aug 06, 2026 |
| CVE-2024-10302 | MEDIUM | 4.0 | The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user … | Aug 06, 2026 |