Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49853
Total
4028
Critical
14819
High
14575
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-67200 | HIGH | 7.5 | Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the server filesystem by including literal ../ segments … | Aug 04, 2026 |
| CVE-2026-67199 | MEDIUM | 6.5 | Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a crafted expression containing … | Aug 04, 2026 |
| CVE-2026-67198 | HIGH | 7.5 | Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server process by sending malformed or … | Aug 04, 2026 |
| CVE-2026-67196 | MEDIUM | 5.4 | Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to inject arbitrary HTML and JavaScript by writing table cell … | Aug 04, 2026 |
| CVE-2026-67195 | HIGH | 8.8 | Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the … | Aug 04, 2026 |
| CVE-2026-61515 | CRITICAL | 9.8 | Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by … | Aug 04, 2026 |
| CVE-2026-61514 | CRITICAL | 9.8 | Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets … | Aug 04, 2026 |
| CVE-2026-18770 | HIGH | 7.3 | A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /code of the component Python Validation … | Aug 04, 2026 |
| CVE-2026-18766 | MEDIUM | 6.3 | A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affects some unknown processing of the file /Applications/MAMP/htdocs/core-php-admin-panel-master/customers.php. Executing a manipulation of … | Aug 04, 2026 |
| CVE-2026-18650 | HIGH | 8.8 | Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYS: from 2.2.3 before 2.3.1. | Aug 04, 2026 |
| CVE-2026-18401 | UNKNOWN | — | The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in StreamReadConstraints (default: 1000 characters). An attacker able to submit JSON … | Aug 04, 2026 |
| CVE-2026-11368 | HIGH | 7.1 | The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data->att_chan = chan). When … | Aug 04, 2026 |
| CVE-2026-70368 | MEDIUM | 6.5 | A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A remote attacker with network access … | Aug 04, 2026 |
| CVE-2026-70367 | MEDIUM | 5.4 | A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to … | Aug 04, 2026 |
| CVE-2026-17070 | HIGH | 8.8 | Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: from 2.2.3 before 2.3.1. | Aug 04, 2026 |
| CVE-2026-14337 | UNKNOWN | — | Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user … | Aug 04, 2026 |
| CVE-2026-70373 | MEDIUM | 6.5 | Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concatenating several user-controlled request parameters directly into the SQL string. The … | Aug 04, 2026 |
| CVE-2026-70372 | MEDIUM | 6.5 | Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Criteria parameter is only normalized … | Aug 04, 2026 |
| CVE-2026-70371 | MEDIUM | 6.5 | Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Line and Column parameters are … | Aug 04, 2026 |
| CVE-2026-70370 | MEDIUM | 6.5 | Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directly into identifier positions of the query (SELECT … | Aug 04, 2026 |
| CVE-2026-70369 | MEDIUM | 6.5 | Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-controlled Filter request parameters directly into WHERE fragments covering aqbasket.closedate, aqorders.datereceived, aqbooksellers.name, … | Aug 04, 2026 |
| CVE-2026-63252 | UNKNOWN | — | In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote … | Aug 04, 2026 |
| CVE-2026-63248 | UNKNOWN | — | In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a … | Aug 04, 2026 |
| CVE-2026-62927 | UNKNOWN | — | In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or … | Aug 04, 2026 |
| CVE-2026-61387 | UNKNOWN | — | In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is … | Aug 04, 2026 |