Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50089
Total
4047
Critical
14897
High
14637
Medium
CVE ID Severity Score Description Published
CVE-2026-18720 MEDIUM 5.3 A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?plugin/msgWarning/action of the component msgWarning Plugin. … Aug 04, 2026
CVE-2026-17614 MEDIUM 4.4 A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getConfigurationFile() methods in wildfly-core/deployment-repository do not validate that the resolved file … Aug 04, 2026
CVE-2026-18719 MEDIUM 6.3 A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the component Search. Performing a manipulation of … Aug 04, 2026
CVE-2026-58045 MEDIUM 6.2 A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. … Aug 04, 2026
CVE-2026-58044 LOW 3.7 A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while … Aug 04, 2026
CVE-2026-58042 MEDIUM 5.9 A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records. Repeated triggering of this … Aug 04, 2026
CVE-2026-58041 MEDIUM 5.3 A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it has been reset and … Aug 04, 2026
CVE-2026-56846 HIGH 7.5 A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and … Aug 04, 2026
CVE-2026-56845 HIGH 7.5 An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an … Aug 04, 2026
CVE-2026-66326 MEDIUM 6.5 Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Aug 04, 2026
CVE-2026-66325 MEDIUM 6.1 Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. Aug 04, 2026
CVE-2026-66322 HIGH 7.1 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. Aug 04, 2026
CVE-2026-66321 HIGH 7.4 Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Aug 04, 2026
CVE-2026-66318 HIGH 8.1 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. Aug 04, 2026
CVE-2026-66317 MEDIUM 5.4 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. Aug 04, 2026
CVE-2026-66316 MEDIUM 5.4 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. Aug 04, 2026
CVE-2026-66315 HIGH 7.5 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Aug 04, 2026
CVE-2026-66314 MEDIUM 6.5 Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. Aug 04, 2026
CVE-2026-66313 MEDIUM 6.8 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. Aug 04, 2026
CVE-2026-66312 MEDIUM 6.5 Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. Aug 04, 2026
CVE-2026-66311 MEDIUM 6.2 Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. Aug 04, 2026
CVE-2026-66310 HIGH 7.7 External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. Aug 04, 2026
CVE-2026-65804 MEDIUM 6.1 Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. Aug 04, 2026
CVE-2026-65802 HIGH 7.4 External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. Aug 04, 2026
CVE-2026-62870 HIGH 8.8 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. Aug 04, 2026