Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50855
Total
4075
Critical
15116
High
14809
Medium
CVE ID Severity Score Description Published
CVE-2026-8497 HIGH 7.4 Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker … Jul 29, 2026
CVE-2026-59920 MEDIUM 6.5 Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's STOMP encoder ( StompSubframeEncoder ) does not escape or … Jul 29, 2026
CVE-2026-59919 MEDIUM 5.5 Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's HAProxy encoder ( HAProxyMessageEncoder ) writes AF_UNIX source and … Jul 29, 2026
CVE-2026-59901 UNKNOWN — Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in Netty's compression codec pipeline is vulnerable to … Jul 29, 2026
CVE-2026-59900 UNKNOWN — Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x translation layer (`Http2StreamFrameToHttpObjectCodec` and `InboundHttp2ToHttpAdapter`) fails to deduplicate or … Jul 29, 2026
CVE-2026-59899 UNKNOWN — Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the superclass of the production handler `HttpContentCompressor`) maintains a per-channel … Jul 29, 2026
CVE-2026-54705 MEDIUM 6.3 MathLive provides web components for math display and input. Prior to 0.110.0, MathLive fails to escape text-mode content in \text{} and \mbox{} commands in Box.toMarkup … Jul 29, 2026
CVE-2026-41939 CRITICAL 9.8 Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access … Jul 29, 2026
CVE-2026-40272 HIGH 7.0 Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) file, to … Jul 29, 2026
CVE-2026-18236 UNKNOWN — A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events … Jul 29, 2026
CVE-2026-14266 HIGH 7.0 7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User … Jul 29, 2026
CVE-2026-13723 MEDIUM 6.5 A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by exploiting a Unicode Normalization … Jul 29, 2026
CVE-2026-8339 UNKNOWN — A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authenticated threat actor who sends … Jul 29, 2026
CVE-2026-8338 UNKNOWN — A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a … Jul 29, 2026
CVE-2026-67194 MEDIUM 6.5 Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process via deeply nested parenthesized SEARCH queries. … Jul 29, 2026
CVE-2026-64560 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwoo decoded and reported a … Jul 29, 2026
CVE-2026-64559 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl Explicitly check the buffer length request structure provided by … Jul 29, 2026
CVE-2026-64558 HIGH 7.8 In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in pkey_pckmo handler implementation Explicitly check the length of the target buffer … Jul 29, 2026
CVE-2026-54727 HIGH 8.2 proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink entries whose linkname referenced another installed container and did … Jul 29, 2026
CVE-2026-54693 UNKNOWN — ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4.0.0 until 4.15.1, the email and phone … Jul 29, 2026
CVE-2026-54680 CRITICAL 9.9 Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such … Jul 29, 2026
CVE-2026-54574 HIGH 8.2 proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain tarball root filesystems through _extract_plain_tar() in proot_distro/commands/install.py and Docker … Jul 29, 2026
CVE-2026-52791 UNKNOWN — fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branch preserves SUID and SGID mode bits in … Jul 29, 2026
CVE-2026-51992 CRITICAL 9.1 SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries function. Jul 29, 2026
CVE-2026-20316 MEDIUM 5.3 A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an … Jul 29, 2026