Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50663
Total
4071
Critical
15059
High
14768
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-59898 | UNKNOWN | — | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or … | Jul 29, 2026 |
| CVE-2026-2482 | LOW | 3.1 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized … | Jul 29, 2026 |
| CVE-2026-16328 | HIGH | 8.6 | In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's … | Jul 29, 2026 |
| CVE-2026-16326 | CRITICAL | 10.0 | In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to … | Jul 29, 2026 |
| CVE-2026-14529 | CRITICAL | 9.4 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) … | Jul 29, 2026 |
| CVE-2026-13346 | UNKNOWN | — | pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This … | Jul 29, 2026 |
| CVE-2026-12935 | UNKNOWN | — | The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based buffer overflow. The issue occurs when … | Jul 29, 2026 |
| CVE-2026-10684 | LOW | 3.0 | In subsys/debug/coredump/coredump_shell.c, print_coredump_hdr() used the 16-bit tgt_code field of a stored Zephyr coredump header directly as an index into coredump_target_code2str[], a fixed 7-element array of … | Jul 29, 2026 |
| CVE-2026-8497 | HIGH | 7.4 | Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker … | Jul 29, 2026 |
| CVE-2026-59920 | MEDIUM | 6.5 | Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's STOMP encoder ( StompSubframeEncoder ) does not escape or … | Jul 29, 2026 |
| CVE-2026-59919 | MEDIUM | 5.5 | Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's HAProxy encoder ( HAProxyMessageEncoder ) writes AF_UNIX source and … | Jul 29, 2026 |
| CVE-2026-59901 | UNKNOWN | — | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to … | Jul 29, 2026 |
| CVE-2026-59900 | UNKNOWN | — | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or … | Jul 29, 2026 |
| CVE-2026-59899 | UNKNOWN | — | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel … | Jul 29, 2026 |
| CVE-2026-54705 | MEDIUM | 6.3 | MathLive provides web components for math display and input. Prior to 0.110.0, MathLive fails to escape text-mode content in \text{} and \mbox{} commands in Box.toMarkup … | Jul 29, 2026 |
| CVE-2026-41939 | CRITICAL | 9.8 | Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access … | Jul 29, 2026 |
| CVE-2026-40272 | HIGH | 7.0 | Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) file, to … | Jul 29, 2026 |
| CVE-2026-18236 | UNKNOWN | — | A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events … | Jul 29, 2026 |
| CVE-2026-14266 | HIGH | 7.0 | 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User … | Jul 29, 2026 |
| CVE-2026-13723 | MEDIUM | 6.5 | A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by exploiting a Unicode Normalization … | Jul 29, 2026 |
| CVE-2026-8339 | UNKNOWN | — | A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authenticated threat actor who sends … | Jul 29, 2026 |
| CVE-2026-8338 | UNKNOWN | — | A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a … | Jul 29, 2026 |
| CVE-2026-67194 | MEDIUM | 6.5 | Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process via deeply nested parenthesized SEARCH queries. … | Jul 29, 2026 |
| CVE-2026-64560 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a … | Jul 29, 2026 |
| CVE-2026-64559 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl Explicitly check the buffer length request structure provided by … | Jul 29, 2026 |