Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50353
Total
4061
Critical
14946
High
14711
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-53503 | HIGH | 7.5 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, <columns>, <should_normalize>) filter passes the user-controlled <columns> value to a C … | Jul 31, 2026 |
| CVE-2026-53502 | UNKNOWN | — | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boundary validation, allowing traversal outside FILE_LOADER_ROOT_PATH … | Jul 31, 2026 |
| CVE-2026-53501 | HIGH | 8.2 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() … | Jul 31, 2026 |
| CVE-2026-53500 | HIGH | 8.2 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a … | Jul 31, 2026 |
| CVE-2026-25552 | LOW | 3.7 | Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a … | Jul 31, 2026 |
| CVE-2026-18481 | HIGH | 7.3 | Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal session tokens … | Jul 31, 2026 |
| CVE-2026-18321 | MEDIUM | 4.7 | Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd | Jul 31, 2026 |
| CVE-2026-55100 | UNKNOWN | — | hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, … | Jul 31, 2026 |
| CVE-2026-54737 | HIGH | 7.3 | @phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges user-supplied objects without filtering proto, … | Jul 31, 2026 |
| CVE-2026-54729 | UNKNOWN | — | DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as … | Jul 31, 2026 |
| CVE-2026-54725 | CRITICAL | 9.6 | vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap … | Jul 31, 2026 |
| CVE-2026-34497 | UNKNOWN | — | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue … | Jul 31, 2026 |
| CVE-2026-34495 | UNKNOWN | — | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems … | Jul 31, 2026 |
| CVE-2026-34490 | UNKNOWN | — | Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve … | Jul 31, 2026 |
| CVE-2026-21662 | UNKNOWN | — | Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before … | Jul 31, 2026 |
| CVE-2026-67822 | CRITICAL | 9.8 | Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters … | Jul 31, 2026 |
| CVE-2026-58048 | UNKNOWN | — | Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. | Jul 31, 2026 |
| CVE-2026-58047 | UNKNOWN | — | HTTP Smuggling in cPanel allows potential leak of credentials. | Jul 31, 2026 |
| CVE-2026-54707 | MEDIUM | 5.4 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior … | Jul 31, 2026 |
| CVE-2026-54706 | MEDIUM | 4.8 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior … | Jul 31, 2026 |
| CVE-2026-52856 | HIGH | 7.5 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP … | Jul 31, 2026 |
| CVE-2026-52855 | CRITICAL | 9.9 | Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow … | Jul 31, 2026 |
| CVE-2026-67607 | MEDIUM | 5.9 | LightFTP 2.3.1 contains a race condition vulnerability that allows remote attackers to crash the server by racing a fresh connection that reuses the FTP context … | Jul 31, 2026 |
| CVE-2026-59232 | UNKNOWN | — | Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead permission to … | Jul 31, 2026 |
| CVE-2026-59231 | UNKNOWN | — | Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server … | Jul 31, 2026 |