Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50353
Total
4061
Critical
14946
High
14711
Medium
CVE ID Severity Score Description Published
CVE-2026-56571 LOW 3.7 HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network timeout, and … Jul 31, 2026
CVE-2026-56570 LOW 3.7 HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers … Jul 31, 2026
CVE-2026-56569 MEDIUM 4.0 HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application … Jul 31, 2026
CVE-2026-56568 LOW 3.7 HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead … Jul 31, 2026
CVE-2026-56567 MEDIUM 5.1 HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application … Jul 31, 2026
CVE-2026-52857 MEDIUM 5.5 Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, unbounded json, yaml, and xml configuration-file parsers … Jul 31, 2026
CVE-2026-18141 HIGH 8.2 A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security … Jul 31, 2026
CVE-2026-17566 CRITICAL 9.9 pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the … Jul 31, 2026
CVE-2026-17351 CRITICAL 9.0 The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly … Jul 31, 2026
CVE-2026-17350 MEDIUM 5.4 The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its permission check consistently. In SERVER mode, … Jul 31, 2026
CVE-2026-17349 CRITICAL 9.6 /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which … Jul 31, 2026
CVE-2026-17348 MEDIUM 6.5 In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, … Jul 31, 2026
CVE-2026-17347 HIGH 7.5 The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the … Jul 31, 2026
CVE-2026-17346 HIGH 8.8 The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several … Jul 31, 2026
CVE-2026-16504 UNKNOWN — Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True. Jul 31, 2026
CVE-2026-16503 UNKNOWN — Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to … Jul 31, 2026
CVE-2026-10686 MEDIUM 5.8 Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing branches of ipv6_route_packet() (subsys/net/ip) were affected: the explicit-route … Jul 31, 2026
CVE-2025-62347 MEDIUM 4.3 HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and potential security bypasses. This was caused by an … Jul 31, 2026
CVE-2026-67350 MEDIUM 4.3 Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious … Jul 31, 2026
CVE-2026-51301 UNKNOWN — Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not … Jul 31, 2026
CVE-2026-51299 UNKNOWN — Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not … Jul 31, 2026
CVE-2026-51289 UNKNOWN — Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not … Jul 31, 2026
CVE-2026-51288 UNKNOWN — Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not … Jul 31, 2026
CVE-2026-51287 UNKNOWN — Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not … Jul 31, 2026
CVE-2026-51286 UNKNOWN — Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not … Jul 31, 2026