Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50855
Total
4075
Critical
15116
High
14809
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-66748 | HIGH | 8.8 | Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code … | Jul 28, 2026 |
| CVE-2026-66746 | MEDIUM | 5.4 | Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote attackers to inject arbitrary response headers by embedding carriage return (0x0D) or … | Jul 28, 2026 |
| CVE-2026-62828 | MEDIUM | 5.4 | Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network. | Jul 28, 2026 |
| CVE-2026-61609 | HIGH | 7.5 | Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProvider::configureRateLimiting() applied a single global bucket … | Jul 28, 2026 |
| CVE-2026-54593 | HIGH | 8.1 | Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid … | Jul 28, 2026 |
| CVE-2026-54545 | HIGH | 7.1 | wakaru is a JavaScript decompiler and unminifier toolkit. From 1.0.0 until 1.4.0, @wakaru/cli sanitizes bundle-controlled module filenames only once before writing extracted modules, so a … | Jul 28, 2026 |
| CVE-2026-51271 | CRITICAL | 9.6 | In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the WAV header parsing function read_WAV_Header(). The function reads untrusted chunk size and bytes-to-skip … | Jul 28, 2026 |
| CVE-2026-51270 | UNKNOWN | — | schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the htmlToUTF8() HTML entity decoding function. The function parses attacker-controlled malicious HTML entities and uses … | Jul 28, 2026 |
| CVE-2026-51269 | HIGH | 8.8 | schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the connecttospeech() function. The application accepts attacker-controlled long speech text input, performs URL encoding, and … | Jul 28, 2026 |
| CVE-2026-51268 | UNKNOWN | — | schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the host parsing logic. The dismantle_host() function parses untrusted host and URL input, and subsequent … | Jul 28, 2026 |
| CVE-2026-51267 | CRITICAL | 9.8 | schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the URL path concatenation and encoding module. The application splices untrusted extension path and attacker-controlled … | Jul 28, 2026 |
| CVE-2026-51266 | CRITICAL | 9.8 | schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the HTTP request header construction logic. The application dynamically splices attacker-controlled host name, path, query … | Jul 28, 2026 |
| CVE-2026-51263 | CRITICAL | 9.8 | schreibfaul1 ESP32-audioI2S 3.4.5 is vulnerable to Buffer Overflow. The Audio::openai_speech function in the Audio library manually constructs JSON request bodies and HTTP request headers by … | Jul 28, 2026 |
| CVE-2026-47483 | HIGH | 8.2 | NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated … | Jul 28, 2026 |
| CVE-2026-47427 | HIGH | 7.5 | GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref without first checking whether it is nil, … | Jul 28, 2026 |
| CVE-2026-45293 | HIGH | 8.6 | WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the … | Jul 28, 2026 |
| CVE-2026-43910 | HIGH | 8.2 | Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2.1 until 10.1.1, when directConnect(true) … | Jul 28, 2026 |
| CVE-2026-8164 | HIGH | 7.3 | Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Order Hijacking. This issue affects ArkSigner … | Jul 28, 2026 |
| CVE-2026-7521 | MEDIUM | 5.5 | Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin with … | Jul 28, 2026 |
| CVE-2026-6879 | UNKNOWN | — | `Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` … | Jul 28, 2026 |
| CVE-2026-67178 | UNKNOWN | — | MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrectly formatted HTTP-to-HTTPS redirect: Redirect permanent / https://misp.example Apache’s Redirect directive appends any portion … | Jul 28, 2026 |
| CVE-2026-67174 | UNKNOWN | — | Pivotick contains a DOM-based cross-site scripting vulnerability in its generic UI element resolution and icon-rendering utilities. The tryResolveHTMLElement function treated any resolved string as HTML … | Jul 28, 2026 |
| CVE-2026-66713 | CRITICAL | 9.8 | Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat (only when Tribes clustering … | Jul 28, 2026 |
| CVE-2026-66299 | HIGH | 7.5 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 … | Jul 28, 2026 |
| CVE-2026-63727 | HIGH | 8.8 | Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is … | Jul 28, 2026 |