Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49645
Total
4014
Critical
14740
High
14481
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-67867 | HIGH | 7.5 | Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Alarm/Conditions wrapper when processing PublishResponse EventNotificationList … | Aug 05, 2026 |
| CVE-2026-67866 | HIGH | 7.5 | Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse and SOPC_StaMac_NewDeleteMonitoredItems in the client … | Aug 05, 2026 |
| CVE-2026-67863 | HIGH | 7.5 | In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after … | Aug 05, 2026 |
| CVE-2026-19026 | UNKNOWN | — | H5Z__filter_nbit in H5Znbit.c in HDF5 through 2.3.0 dereferences cd_values[0] through cd_values[4] without validating that cd_values is non-NULL or that cd_nelmts is at least 5, the … | Aug 05, 2026 |
| CVE-2026-19025 | UNKNOWN | — | H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset's stored chunk-layout dimensionality matches its dataspace rank when an existing dataset … | Aug 05, 2026 |
| CVE-2026-19024 | UNKNOWN | — | NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.3.0 allows attackers to cause a denial of service via a dataset whose version 1 or 2 … | Aug 05, 2026 |
| CVE-2026-19023 | UNKNOWN | — | Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.3.0 allows attackers to cause a denial of service via a … | Aug 05, 2026 |
| CVE-2026-71321 | HIGH | 7.5 | Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_island/...` decodes and hashes attacker-controlled … | Aug 05, 2026 |
| CVE-2026-71320 | HIGH | 8.1 | Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props … | Aug 05, 2026 |
| CVE-2026-71319 | CRITICAL | 9.6 | Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite … | Aug 05, 2026 |
| CVE-2026-71318 | MEDIUM | 4.8 | Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply a top-level `as` prop to the … | Aug 05, 2026 |
| CVE-2026-71316 | HIGH | 7.5 | Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for /<page>/_payload.json can be returned before route middleware and … | Aug 05, 2026 |
| CVE-2026-67865 | HIGH | 7.5 | S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling. This allows a remote attacker to cause a denial of service | Aug 05, 2026 |
| CVE-2026-67864 | HIGH | 7.5 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic component | Aug 05, 2026 |
| CVE-2025-63823 | CRITICAL | 9.8 | My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user … | Aug 05, 2026 |
| CVE-2025-63822 | HIGH | 8.1 | SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized … | Aug 05, 2026 |
| CVE-2026-71315 | HIGH | 8.2 | Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-folded lookups when … | Aug 05, 2026 |
| CVE-2026-71314 | HIGH | 7.5 | Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, … | Aug 05, 2026 |
| CVE-2026-71313 | MEDIUM | 6.9 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local backend in … | Aug 05, 2026 |
| CVE-2026-71312 | HIGH | 8.0 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths … | Aug 05, 2026 |
| CVE-2026-71311 | MEDIUM | 6.4 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, a valid but nondefault FTP … | Aug 05, 2026 |
| CVE-2026-71310 | MEDIUM | 5.9 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNECT helper … | Aug 05, 2026 |
| CVE-2026-71309 | UNKNOWN | — | rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve restic does … | Aug 05, 2026 |
| CVE-2026-34966 | HIGH | 7.6 | Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiting HTTP fetch operations in migration … | Aug 05, 2026 |
| CVE-2026-18959 | MEDIUM | 5.4 | A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::destroyFiles of the file innopacks/restapi/routes/panel-api.php of the … | Aug 05, 2026 |