Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50089
Total
4047
Critical
14897
High
14637
Medium
CVE ID Severity Score Description Published
CVE-2026-17070 HIGH 8.8 Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: from 2.2.3 before 2.3.1. Aug 04, 2026
CVE-2026-14337 UNKNOWN Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user … Aug 04, 2026
CVE-2026-70373 MEDIUM 6.5 Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concatenating several user-controlled request parameters directly into the SQL string. The … Aug 04, 2026
CVE-2026-70372 MEDIUM 6.5 Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Criteria parameter is only normalized … Aug 04, 2026
CVE-2026-70371 MEDIUM 6.5 Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Line and Column parameters are … Aug 04, 2026
CVE-2026-70370 MEDIUM 6.5 Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directly into identifier positions of the query (SELECT … Aug 04, 2026
CVE-2026-70369 MEDIUM 6.5 Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-controlled Filter request parameters directly into WHERE fragments covering aqbasket.closedate, aqorders.datereceived, aqbooksellers.name, … Aug 04, 2026
CVE-2026-63252 UNKNOWN In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote … Aug 04, 2026
CVE-2026-63248 UNKNOWN In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a … Aug 04, 2026
CVE-2026-62927 UNKNOWN In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or … Aug 04, 2026
CVE-2026-61387 UNKNOWN In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is … Aug 04, 2026
CVE-2026-60007 UNKNOWN In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path … Aug 04, 2026
CVE-2026-58080 UNKNOWN In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running … Aug 04, 2026
CVE-2026-18809 MEDIUM 6.5 Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153.0.3. Aug 04, 2026
CVE-2026-18806 HIGH 7.1 External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. This issue affects pardus-image-writer: … Aug 04, 2026
CVE-2026-10710 HIGH 7.8 A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage … Aug 04, 2026
CVE-2026-10709 HIGH 7.8 A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage … Aug 04, 2026
CVE-2026-66884 UNKNOWN Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback module) allows an attacker to make a victim's browser complete an authorization flow the victim … Aug 04, 2026
CVE-2026-66883 UNKNOWN Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize module) renders the user agent session binding inert, removing a defense in depth … Aug 04, 2026
CVE-2026-10050 UNKNOWN In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP … Aug 04, 2026
CVE-2026-18772 MEDIUM 5.5 Improper input validation vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. Aug 04, 2026
CVE-2026-15721 CRITICAL 9.8 Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital … Aug 04, 2026
CVE-2026-14838 HIGH 7.4 Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Session Hijacking. This … Aug 04, 2026
CVE-2026-14804 CRITICAL 9.1 Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. This … Aug 04, 2026
CVE-2026-14465 MEDIUM 6.5 Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Session IDs (aka Session Replay). This issue affects … Aug 04, 2026