Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50855
Total
4075
Critical
15116
High
14809
Medium
CVE ID Severity Score Description Published
CVE-2026-58150 CRITICAL 10.0 Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from … Jul 29, 2026
CVE-2026-57834 CRITICAL 10.0 Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, … Jul 29, 2026
CVE-2026-41920 CRITICAL 9.3 Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended … Jul 29, 2026
CVE-2026-35226 MEDIUM 6.5 An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that … Jul 29, 2026
CVE-2026-33930 MEDIUM 5.9 Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows … Jul 29, 2026
CVE-2026-33267 CRITICAL 10.0 Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended … Jul 29, 2026
CVE-2026-24033 HIGH 7.2 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3, from 9.0.0 … Jul 29, 2026
CVE-2026-22068 HIGH 8.2 Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are … Jul 29, 2026
CVE-2026-18197 UNKNOWN — Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allows Cross-Site Scripting (XSS). This issue affects Link Library: before 7.9.4. Jul 29, 2026
CVE-2026-18192 MEDIUM 6.5 VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files. Jul 29, 2026
CVE-2026-18191 CRITICAL 9.8 VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administrator credentials of … Jul 29, 2026
CVE-2026-63242 MEDIUM 4.3 A business logic vulnerability in Koollab LMS allowed an authenticated learner to set their lesson completion status to completed via the SCORM commit endpoint without … Jul 29, 2026
CVE-2026-63241 LOW 3.1 An insecure direct object reference vulnerability in Koollab LMS allowed an authenticated user to query the course completion progress of any other user without authorisation, … Jul 29, 2026
CVE-2026-63240 MEDIUM 4.3 An information disclosure vulnerability in Koollab LMS allowed an authenticated learner to obtain correct quiz answers from the course status endpoint without completing the assessment … Jul 29, 2026
CVE-2026-63239 MEDIUM 5.4 A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and … Jul 29, 2026
CVE-2026-63238 MEDIUM 6.5 An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, including administrator accounts, by supplying a valid user UUID … Jul 29, 2026
CVE-2026-63237 MEDIUM 4.8 A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled seed to generate a matching one-time password and bypass … Jul 29, 2026
CVE-2026-63236 LOW 3.7 An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name, internal identifier, scores, lesson status, lesson position, and … Jul 29, 2026
CVE-2026-63235 LOW 3.7 An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the session of any user given their email address via … Jul 29, 2026
CVE-2026-63234 CRITICAL 9.9 A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed … Jul 29, 2026
CVE-2026-63233 CRITICAL 9.9 A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed … Jul 29, 2026
CVE-2026-63232 CRITICAL 9.9 A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to … Jul 29, 2026
CVE-2026-63231 HIGH 8.1 A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-face runs update endpoint to … Jul 29, 2026
CVE-2026-63230 CRITICAL 9.1 A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, credentials, and valid … Jul 29, 2026
CVE-2026-63229 CRITICAL 9.1 A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to … Jul 29, 2026