Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50855
Total
4075
Critical
15116
High
14809
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-18257 | MEDIUM | 5.6 | Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a certificate issued by this root issuer to be considered … | Jul 29, 2026 |
| CVE-2026-18255 | HIGH | 7.2 | A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member … | Jul 29, 2026 |
| CVE-2026-16729 | MEDIUM | 4.8 | undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before … | Jul 29, 2026 |
| CVE-2026-15144 | HIGH | 7.3 | @fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Because a single IPv6 client can control a large address … | Jul 29, 2026 |
| CVE-2026-13697 | HIGH | 7.4 | undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a … | Jul 29, 2026 |
| CVE-2025-60931 | HIGH | 7.5 | An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allows unauthorized attackers to arbitrarily view the compensation … | Jul 29, 2026 |
| CVE-2026-67193 | MEDIUM | 5.3 | Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the server's current GetTickCount() value by sending a USER … | Jul 29, 2026 |
| CVE-2026-67192 | HIGH | 8.1 | Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt stack memory by sending malformed SSH packets … | Jul 29, 2026 |
| CVE-2026-67191 | CRITICAL | 9.8 | Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap … | Jul 29, 2026 |
| CVE-2026-67188 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Jul 29, 2026 |
| CVE-2026-66051 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Jul 29, 2026 |
| CVE-2026-60113 | CRITICAL | 9.8 | AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that … | Jul 29, 2026 |
| CVE-2026-60112 | CRITICAL | 9.8 | AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue … | Jul 29, 2026 |
| CVE-2026-54735 | CRITICAL | 10.0 | Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate … | Jul 29, 2026 |
| CVE-2026-54082 | MEDIUM | 6.5 | veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity vulnerability in … | Jul 29, 2026 |
| CVE-2026-54081 | UNKNOWN | — | veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service vulnerability in veraPDF-parser/src/main/java/org/verapdf/pd/font/type1/Type1FontProgram.java and veraPDF-parser/src/main/java/org/verapdf/parser/postscript/PSOperator.java, where a … | Jul 29, 2026 |
| CVE-2026-54080 | UNKNOWN | — | veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service vulnerability in veraPDF-parser/src/main/java/org/verapdf/pd/font/cmap/CMapParser.java and veraPDF-parser/src/main/java/org/verapdf/parser/postscript/PSOperator.java, where a … | Jul 29, 2026 |
| CVE-2026-54079 | UNKNOWN | — | veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) … | Jul 29, 2026 |
| CVE-2026-54078 | UNKNOWN | — | veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulnerability … | Jul 29, 2026 |
| CVE-2026-50558 | MEDIUM | 5.9 | Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in penelope.py used tar.extractall(local_download_folder) on tar … | Jul 29, 2026 |
| CVE-2026-17550 | MEDIUM | 5.5 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability … | Jul 29, 2026 |
| CVE-2026-16543 | UNKNOWN | — | Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. … | Jul 29, 2026 |
| CVE-2026-16465 | MEDIUM | 6.1 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability … | Jul 29, 2026 |
| CVE-2026-16463 | HIGH | 7.8 | A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause … | Jul 29, 2026 |
| CVE-2026-15228 | UNKNOWN | — | Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. KIC collects CA-certificate … | Jul 29, 2026 |