Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50855
Total
4075
Critical
15116
High
14809
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-67183 | HIGH | 7.5 | TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well-formed HTTP requests. Each request causes … | Jul 28, 2026 |
| CVE-2026-67182 | HIGH | 7.5 | Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass access controls by injecting bare line feed characters (0x0A) … | Jul 28, 2026 |
| CVE-2026-54620 | UNKNOWN | — | sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still … | Jul 28, 2026 |
| CVE-2026-54619 | UNKNOWN | — | sqlite3 provides Ruby bindings for the SQLite3 embedded database. In version 2.9.4 and earlier, redefining a SQLite function with a different arity frees the previously … | Jul 28, 2026 |
| CVE-2026-54609 | HIGH | 8.6 | QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets to the host without bounding … | Jul 28, 2026 |
| CVE-2026-54605 | HIGH | 7.2 | OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location … | Jul 28, 2026 |
| CVE-2026-54603 | HIGH | 8.6 | OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location … | Jul 28, 2026 |
| CVE-2026-54345 | UNKNOWN | — | gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed … | Jul 28, 2026 |
| CVE-2026-54332 | UNKNOWN | — | gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads an attacker-controlled 32-bit community count and … | Jul 28, 2026 |
| CVE-2026-51275 | HIGH | 8.8 | In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 APIC frame parsing function in audiolib allows remote attackers to execute arbitrary code or … | Jul 28, 2026 |
| CVE-2026-51274 | HIGH | 8.8 | In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 SYLT synchronized lyrics parser in audiolib allows remote attackers to cause a denial of … | Jul 28, 2026 |
| CVE-2026-51273 | HIGH | 7.8 | In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the ID3 tag parsing function showID3Tag() of the embedded audio streaming library. The program … | Jul 28, 2026 |
| CVE-2026-18085 | UNKNOWN | — | An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of … | Jul 28, 2026 |
| CVE-2026-18084 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS). This issue affects UEM: … | Jul 28, 2026 |
| CVE-2026-16313 | HIGH | 7.6 | A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI … | Jul 28, 2026 |
| CVE-2026-8058 | MEDIUM | 4.5 | IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows a user to supply a password with a resource dump request stores that password into … | Jul 28, 2026 |
| CVE-2026-7868 | MEDIUM | 6.5 | IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges and give themselves administrator privileges. | Jul 28, 2026 |
| CVE-2026-7775 | MEDIUM | 5.5 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, … | Jul 28, 2026 |
| CVE-2026-67181 | MEDIUM | 5.4 | Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize HTTP message boundaries by exploiting improper header forwarding in … | Jul 28, 2026 |
| CVE-2026-66754 | MEDIUM | 5.9 | Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a … | Jul 28, 2026 |
| CVE-2026-66753 | LOW | 3.7 | tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return (0x0D) and line feed (0x0A) bytes into HTTP header … | Jul 28, 2026 |
| CVE-2026-66752 | MEDIUM | 5.4 | tiny-http through 0.12.0 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize request framing by sending a Transfer-Encoding header with any value, … | Jul 28, 2026 |
| CVE-2026-66751 | MEDIUM | 5.4 | Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to archive any room on the server by sending a … | Jul 28, 2026 |
| CVE-2026-66750 | MEDIUM | 4.3 | Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authenticated attackers to download file attachments from private and password-protected rooms they … | Jul 28, 2026 |
| CVE-2026-66749 | MEDIUM | 6.5 | Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows authenticated attackers to crash the server by supplying a valid 24-character hex string … | Jul 28, 2026 |