Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50855
Total
4075
Critical
15116
High
14809
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-48394 | HIGH | 7.8 | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this … | Jul 28, 2026 |
| CVE-2026-48393 | HIGH | 7.8 | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this … | Jul 28, 2026 |
| CVE-2026-48392 | HIGH | 7.8 | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this … | Jul 28, 2026 |
| CVE-2026-48391 | HIGH | 8.2 | Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged … | Jul 28, 2026 |
| CVE-2026-48390 | HIGH | 8.2 | Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and … | Jul 28, 2026 |
| CVE-2026-48374 | HIGH | 7.8 | Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. … | Jul 28, 2026 |
| CVE-2026-48058 | UNKNOWN | — | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/web/session.go and internal/web/oidc.go set HttpOnly and SameSite=Lax on … | Jul 28, 2026 |
| CVE-2026-47768 | MEDIUM | 5.5 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minted operator API key exposed in redirect URL … | Jul 28, 2026 |
| CVE-2026-47726 | UNKNOWN | — | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/api/audit.go:12 — handleGetAuditLog does no admin check. The … | Jul 28, 2026 |
| CVE-2026-47725 | UNKNOWN | — | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every /ui/* POST / PUT / PATCH / … | Jul 28, 2026 |
| CVE-2026-18107 | HIGH | 7.8 | A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an rseq critical section … | Jul 28, 2026 |
| CVE-2026-16771 | HIGH | 8.8 | In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side … | Jul 28, 2026 |
| CVE-2026-16498 | CRITICAL | 10.0 | The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform … | Jul 28, 2026 |
| CVE-2026-16496 | HIGH | 8.9 | The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another … | Jul 28, 2026 |
| CVE-2026-15992 | HIGH | 8.8 | The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing … | Jul 28, 2026 |
| CVE-2026-15304 | MEDIUM | 6.5 | The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions up to, and including, 10.2.4. This is due … | Jul 28, 2026 |
| CVE-2026-14869 | HIGH | 8.6 | The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to … | Jul 28, 2026 |
| CVE-2026-59933 | HIGH | 7.5 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through … | Jul 28, 2026 |
| CVE-2026-59931 | HIGH | 7.7 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through … | Jul 28, 2026 |
| CVE-2026-54635 | HIGH | 7.5 | pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.0.0 to 2.2.0, TonapiWebhookDispatcher fails … | Jul 28, 2026 |
| CVE-2026-48388 | HIGH | 8.6 | Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the … | Jul 28, 2026 |
| CVE-2026-48372 | HIGH | 7.8 | Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation … | Jul 28, 2026 |
| CVE-2026-48025 | UNKNOWN | — | nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.7, internal/pki/resolver.go:36-64 constructs a CAManager with the plaintext ed25519.PrivateKey … | Jul 28, 2026 |
| CVE-2026-67185 | HIGH | 7.5 | TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting ../ sequences in the URL path, which … | Jul 28, 2026 |
| CVE-2026-67184 | HIGH | 7.5 | TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to crash worker processes by sending a malformed HTTP request line … | Jul 28, 2026 |