Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50663
Total
4071
Critical
15059
High
14768
Medium
CVE ID Severity Score Description Published
CVE-2026-54079 UNKNOWN — veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) … Jul 29, 2026
CVE-2026-54078 UNKNOWN — veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulnerability … Jul 29, 2026
CVE-2026-50558 MEDIUM 5.9 Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in penelope.py used tar.extractall(local_download_folder) on tar … Jul 29, 2026
CVE-2026-17550 MEDIUM 5.5 A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability … Jul 29, 2026
CVE-2026-16543 UNKNOWN — Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. … Jul 29, 2026
CVE-2026-16465 MEDIUM 6.1 A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability … Jul 29, 2026
CVE-2026-16463 HIGH 7.8 A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause … Jul 29, 2026
CVE-2026-15228 UNKNOWN — Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. KIC collects CA-certificate … Jul 29, 2026
CVE-2026-66724 UNKNOWN — MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload endpoints. These endpoints accept the undocumented POST … Jul 29, 2026
CVE-2026-66723 UNKNOWN — MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. The proxy API does not verify authentication for … Jul 29, 2026
CVE-2026-65947 UNKNOWN — Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2 Jul 29, 2026
CVE-2026-65888 UNKNOWN — Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on … Jul 29, 2026
CVE-2026-65887 UNKNOWN — Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing … Jul 29, 2026
CVE-2026-65886 UNKNOWN — Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files. Jul 29, 2026
CVE-2026-59247 UNKNOWN — Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute forged Hex package contents during dependency resolution. During dependency … Jul 29, 2026
CVE-2026-54666 HIGH 8.3 swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts passes OpenAPI path keys through parseRouteName to templates/default/procedure-call.ejs and … Jul 29, 2026
CVE-2026-54664 HIGH 8.3 swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parsers/enum.ts passes components.schemas.*.enum[i] values to Ts.StringValue in src/configuration.ts without escaping … Jul 29, 2026
CVE-2026-54663 MEDIUM 6.1 swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts warmUpRemoteSchemasCache resolves external $ref URLs and fetchRemoteSchemaDocument uses isHttpUrl to … Jul 29, 2026
CVE-2026-54662 HIGH 8.3 swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfig copies servers[0].url into apiConfig.baseUrl, and templates/base/http-clients/fetch-http-client.ejs interpolates apiConfig.baseUrl into … Jul 29, 2026
CVE-2026-54661 HIGH 8.3 swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-http-client.ejs interpolates servers[0].url from src/code-gen-process.ts into the HttpClient constructor without … Jul 29, 2026
CVE-2026-54660 HIGH 7.4 swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemoteRequestHeaders forwards --authorizationToken to every URL fetched by fetchRemoteSchemaDocument while … Jul 29, 2026
CVE-2026-12703 HIGH 8.0 TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured … Jul 29, 2026
CVE-2026-9177 UNKNOWN — A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This flaw allows an … Jul 29, 2026
CVE-2026-67217 MEDIUM 5.3 cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or … Jul 29, 2026
CVE-2026-67216 MEDIUM 5.9 cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each … Jul 29, 2026