Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50129
Total
4051
Critical
14904
High
14658
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-48326 | CRITICAL | 9.9 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in … | Aug 03, 2026 |
| CVE-2026-48323 | CRITICAL | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code … | Aug 03, 2026 |
| CVE-2026-48317 | CRITICAL | 9.6 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code … | Aug 03, 2026 |
| CVE-2026-18684 | CRITICAL | 9.8 | A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. … | Aug 03, 2026 |
| CVE-2026-18667 | CRITICAL | 9.6 | A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to … | Aug 03, 2026 |
| CVE-2026-69249 | UNKNOWN | — | python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, when resolving invalid certificate chains that include duplicate … | Aug 03, 2026 |
| CVE-2026-69248 | UNKNOWN | — | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrained CA permits the DNS … | Aug 03, 2026 |
| CVE-2026-69247 | UNKNOWN | — | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome … | Aug 03, 2026 |
| CVE-2026-67977 | UNKNOWN | — | An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input. | Aug 03, 2026 |
| CVE-2026-67975 | UNKNOWN | — | Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands. | Aug 03, 2026 |
| CVE-2026-67974 | UNKNOWN | — | A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial … | Aug 03, 2026 |
| CVE-2026-67973 | UNKNOWN | — | An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs. | Aug 03, 2026 |
| CVE-2026-67970 | UNKNOWN | — | Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal. | Aug 03, 2026 |
| CVE-2026-67969 | UNKNOWN | — | An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry. | Aug 03, 2026 |
| CVE-2026-67617 | MEDIUM | 4.8 | Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting … | Aug 03, 2026 |
| CVE-2026-67616 | MEDIUM | 4.3 | Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create … | Aug 03, 2026 |
| CVE-2026-48115 | UNKNOWN | — | Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a vulnerability in … | Aug 03, 2026 |
| CVE-2026-47746 | UNKNOWN | — | Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulnerable to timing attacks during JSON-LD signature … | Aug 03, 2026 |
| CVE-2026-46714 | UNKNOWN | — | Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain a vulnerability that can cause the Misskey … | Aug 03, 2026 |
| CVE-2026-46713 | UNKNOWN | — | Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation … | Aug 03, 2026 |
| CVE-2026-46712 | UNKNOWN | — | Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain a vulnerability where a lack of proper … | Aug 03, 2026 |
| CVE-2026-18682 | LOW | 3.1 | A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api/upload of the component File Upload … | Aug 03, 2026 |
| CVE-2026-10849 | HIGH | 8.2 | The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). … | Aug 03, 2026 |
| CVE-2026-69246 | HIGH | 7.2 | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host … | Aug 03, 2026 |
| CVE-2026-69245 | MEDIUM | 6.5 | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes … | Aug 03, 2026 |