Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51159
Total
4081
Critical
15166
High
14812
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-67174 | UNKNOWN | — | Pivotick contains a DOM-based cross-site scripting vulnerability in its generic UI element resolution and icon-rendering utilities. The tryResolveHTMLElement function treated any resolved string as HTML … | Jul 28, 2026 |
| CVE-2026-66713 | CRITICAL | 9.8 | Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat (only when Tribes clustering … | Jul 28, 2026 |
| CVE-2026-66299 | HIGH | 7.5 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 … | Jul 28, 2026 |
| CVE-2026-63727 | HIGH | 8.8 | Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is … | Jul 28, 2026 |
| CVE-2026-51261 | UNKNOWN | — | Missing mutex synchronization in AudioBuffer::freeSpace() in schreibfaul1 ESP32-audioI2S 3.4.5 creates a race condition between concurrent tasks. The function calculates available buffer space without protecting shared … | Jul 28, 2026 |
| CVE-2026-51260 | CRITICAL | 9.4 | Unsafe fixed-size memcpy operation in AudioBuffer::writeSpace() of schreibfaul1 ESP32-audioI2S 3.4.5 allows remote heap buffer overflow. The code copies a full UINT16_MAX bytes without validating destination … | Jul 28, 2026 |
| CVE-2026-51259 | CRITICAL | 9.8 | Unchecked unsigned integer overflow in buffer size calculation in schreibfaul1 ESP32-audioI2S 3.4.5 leads to undersized PSRAM buffer allocation. Subsequent normal audio buffer read and write … | Jul 28, 2026 |
| CVE-2026-51254 | HIGH | 7.8 | schreibfaul1 ESP32-audioI2S v3.4.5 has an integer underflow vulnerability in the MP3Decoder::GetBits() function of the MP3 decoder due to unchecked bit reading operations. The lack of … | Jul 28, 2026 |
| CVE-2026-51252 | CRITICAL | 9.8 | schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function due to missing input validation on attacker-controlled MP3 metadata. | Jul 28, 2026 |
| CVE-2026-51251 | HIGH | 7.5 | Schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::decode() function of the MP3 decoder due to missing size validation on untrusted mainDataBegin and … | Jul 28, 2026 |
| CVE-2026-67173 | UNKNOWN | — | Pivotick did not validate the URL scheme of node imagePath values derived from graph data before assigning them to SVG image resources. An attacker able … | Jul 28, 2026 |
| CVE-2026-66922 | UNKNOWN | — | Pivotick used plain JavaScript objects as lookup tables indexed by caller-controlled graph node identifiers in its tree-layout and cycle-detection components. Node identifiers matching properties inherited … | Jul 28, 2026 |
| CVE-2026-66921 | UNKNOWN | — | Pivotick’s Markdown node-reference renderer failed to HTML-escape the attacker-controlled nodeName value before interpolating it into both the data-node-name attribute and the body of a generated … | Jul 28, 2026 |
| CVE-2026-61487 | MEDIUM | 6.5 | Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL by sending to … | Jul 28, 2026 |
| CVE-2026-59878 | HIGH | 7.5 | Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach an exposed AMQP NIO connector … | Jul 28, 2026 |
| CVE-2026-7187 | HIGH | 8.8 | Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects UKBS: through 28072026. … | Jul 28, 2026 |
| CVE-2026-66920 | UNKNOWN | — | Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph and node data. The affected graph algorithms recursively traversed graph edges, while the JSON viewer recursively … | Jul 28, 2026 |
| CVE-2026-66919 | UNKNOWN | — | Pivotick contains a cross-site scripting vulnerability in the inspect and edit node modals. Node labels and descriptions originating from graph data were interpolated directly into … | Jul 28, 2026 |
| CVE-2026-66918 | UNKNOWN | — | Pivotick fails to sanitize attacker-controlled SVG markup supplied through the per-node style.svgIcon property before inserting it into the document. When rendering a graph node, the … | Jul 28, 2026 |
| CVE-2026-66913 | UNKNOWN | — | Lookyloo did not enforce limits on the decompressed size of uploaded capture archives and compressed HAR files. An attacker could submit a specially crafted ZIP, … | Jul 28, 2026 |
| CVE-2026-65882 | MEDIUM | 6.1 | Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url parameter of the moodle wrapper endpoint allowed a reflected … | Jul 28, 2026 |
| CVE-2026-65881 | HIGH | 7.5 | Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1 - The default configuration of the extension allowed … | Jul 28, 2026 |
| CVE-2026-62436 | MEDIUM | 6.5 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] With the introduction of Grant Table v2 came … | Jul 28, 2026 |
| CVE-2026-62435 | MEDIUM | 6.5 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] With the introduction of Grant Table v2 came … | Jul 28, 2026 |
| CVE-2026-62434 | MEDIUM | 5.3 | A guest started with Populated on Demand enabled (PoD) can attempt to reclaim pages which aren't regular guest RAM. This can cause corruption of memory … | Jul 28, 2026 |