Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51159
Total
4081
Critical
15166
High
14812
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-16543 | UNKNOWN | — | Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. … | Jul 29, 2026 |
| CVE-2026-16465 | MEDIUM | 6.1 | A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability … | Jul 29, 2026 |
| CVE-2026-16463 | HIGH | 7.8 | A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause … | Jul 29, 2026 |
| CVE-2026-15228 | UNKNOWN | — | Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. KIC collects CA-certificate … | Jul 29, 2026 |
| CVE-2026-66724 | UNKNOWN | — | MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload endpoints. These endpoints accept the undocumented POST … | Jul 29, 2026 |
| CVE-2026-66723 | UNKNOWN | — | MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. The proxy API does not verify authentication for … | Jul 29, 2026 |
| CVE-2026-65947 | UNKNOWN | — | Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2 | Jul 29, 2026 |
| CVE-2026-65888 | UNKNOWN | — | Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on … | Jul 29, 2026 |
| CVE-2026-65887 | UNKNOWN | — | Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing … | Jul 29, 2026 |
| CVE-2026-65886 | UNKNOWN | — | Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view arbitrary files. | Jul 29, 2026 |
| CVE-2026-59247 | UNKNOWN | — | Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute forged Hex package contents during dependency resolution. During dependency … | Jul 29, 2026 |
| CVE-2026-54666 | HIGH | 8.3 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts passes OpenAPI path keys through parseRouteName to templates/default/procedure-call.ejs and … | Jul 29, 2026 |
| CVE-2026-54664 | HIGH | 8.3 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parsers/enum.ts passes components.schemas.*.enum[i] values to Ts.StringValue in src/configuration.ts without escaping … | Jul 29, 2026 |
| CVE-2026-54663 | MEDIUM | 6.1 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts warmUpRemoteSchemasCache resolves external $ref URLs and fetchRemoteSchemaDocument uses isHttpUrl to … | Jul 29, 2026 |
| CVE-2026-54662 | HIGH | 8.3 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfig copies servers[0].url into apiConfig.baseUrl, and templates/base/http-clients/fetch-http-client.ejs interpolates apiConfig.baseUrl into … | Jul 29, 2026 |
| CVE-2026-54661 | HIGH | 8.3 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-http-client.ejs interpolates servers[0].url from src/code-gen-process.ts into the HttpClient constructor without … | Jul 29, 2026 |
| CVE-2026-54660 | HIGH | 7.4 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemoteRequestHeaders forwards --authorizationToken to every URL fetched by fetchRemoteSchemaDocument while … | Jul 29, 2026 |
| CVE-2026-12703 | HIGH | 8.0 | TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured … | Jul 29, 2026 |
| CVE-2026-9177 | UNKNOWN | — | A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This flaw allows an … | Jul 29, 2026 |
| CVE-2026-67217 | MEDIUM | 5.3 | cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing its value member, or … | Jul 29, 2026 |
| CVE-2026-67216 | MEDIUM | 5.9 | cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each … | Jul 29, 2026 |
| CVE-2026-67215 | HIGH | 7.5 | cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). … | Jul 29, 2026 |
| CVE-2026-67214 | MEDIUM | 5.9 | nanoid (Nano ID) before 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given … | Jul 29, 2026 |
| CVE-2026-67213 | MEDIUM | 5.9 | nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, … | Jul 29, 2026 |
| CVE-2026-66490 | MEDIUM | 6.1 | Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2 | Jul 29, 2026 |