Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49853
Total
4028
Critical
14819
High
14575
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-60007 | UNKNOWN | — | In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path … | Aug 04, 2026 |
| CVE-2026-58080 | UNKNOWN | — | In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running … | Aug 04, 2026 |
| CVE-2026-18809 | MEDIUM | 6.5 | Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153.0.3. | Aug 04, 2026 |
| CVE-2026-18806 | HIGH | 7.1 | External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. This issue affects pardus-image-writer: … | Aug 04, 2026 |
| CVE-2026-10710 | HIGH | 7.8 | A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage … | Aug 04, 2026 |
| CVE-2026-10709 | HIGH | 7.8 | A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage … | Aug 04, 2026 |
| CVE-2026-66884 | UNKNOWN | — | Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback module) allows an attacker to make a victim's browser complete an authorization flow the victim … | Aug 04, 2026 |
| CVE-2026-66883 | UNKNOWN | — | Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize module) renders the user agent session binding inert, removing a defense in depth … | Aug 04, 2026 |
| CVE-2026-10050 | UNKNOWN | — | In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP … | Aug 04, 2026 |
| CVE-2026-18772 | MEDIUM | 5.5 | Improper input validation vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. | Aug 04, 2026 |
| CVE-2026-15721 | CRITICAL | 9.8 | Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital … | Aug 04, 2026 |
| CVE-2026-14838 | HIGH | 7.4 | Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Session Hijacking. This … | Aug 04, 2026 |
| CVE-2026-14804 | CRITICAL | 9.1 | Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. This … | Aug 04, 2026 |
| CVE-2026-14465 | MEDIUM | 6.5 | Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay). This issue affects … | Aug 04, 2026 |
| CVE-2026-14219 | MEDIUM | 5.4 | URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Phishing. This issue affects HUMANIST … | Aug 04, 2026 |
| CVE-2026-14202 | MEDIUM | 5.3 | Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Footprinting. This issue affects HUMANIST Digital Human Resources: … | Aug 04, 2026 |
| CVE-2026-14194 | MEDIUM | 6.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Path … | Aug 04, 2026 |
| CVE-2026-14192 | MEDIUM | 5.4 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Stored XSS. … | Aug 04, 2026 |
| CVE-2026-14175 | CRITICAL | 9.8 | Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to … | Aug 04, 2026 |
| CVE-2026-67243 | HIGH | 7.2 | freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may … | Aug 04, 2026 |
| CVE-2026-18759 | UNKNOWN | — | The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by AES encryption. Because the … | Aug 04, 2026 |
| CVE-2026-18755 | HIGH | 7.3 | A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to execute arbitrary code. By placing … | Aug 04, 2026 |
| CVE-2026-18754 | CRITICAL | 9.1 | The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows … | Aug 04, 2026 |
| CVE-2026-18753 | CRITICAL | 9.1 | The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows … | Aug 04, 2026 |
| CVE-2026-64565 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() The `ims_pcu_process_data()` processes incoming URB data byte by … | Aug 04, 2026 |