Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51181
Total
4084
Critical
15175
High
14817
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-55685 | UNKNOWN | — | React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put … | Jul 27, 2026 |
| CVE-2026-53669 | UNKNOWN | — | React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in <Link> and useNavigate. This … | Jul 27, 2026 |
| CVE-2026-53668 | MEDIUM | 6.9 | React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. … | Jul 27, 2026 |
| CVE-2026-53667 | MEDIUM | 6.9 | React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This … | Jul 27, 2026 |
| CVE-2026-53666 | MEDIUM | 6.1 | React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to … | Jul 27, 2026 |
| CVE-2026-51564 | MEDIUM | 4.9 | An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external URLs via a crafted request. | Jul 27, 2026 |
| CVE-2026-51078 | HIGH | 7.5 | An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the str parameter of the file_manage_control.php component | Jul 27, 2026 |
| CVE-2026-51077 | HIGH | 7.5 | SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the sqlquery parameter of the sys_sql_query.php component | Jul 27, 2026 |
| CVE-2021-32088 | CRITICAL | 9.8 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This … | Jul 27, 2026 |
| CVE-2021-32087 | UNKNOWN | — | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of … | Jul 27, 2026 |
| CVE-2021-32086 | CRITICAL | 9.8 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL … | Jul 27, 2026 |
| CVE-2021-32085 | HIGH | 8.8 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have … | Jul 27, 2026 |
| CVE-2021-32084 | CRITICAL | 9.8 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or … | Jul 27, 2026 |
| CVE-2026-66825 | UNKNOWN | — | Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component. Values associated with link-like properties, such as url, uri, href, link, website, or homepage, … | Jul 27, 2026 |
| CVE-2026-66824 | UNKNOWN | — | A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the serialized capture tree directly into an inline JavaScript block … | Jul 27, 2026 |
| CVE-2026-64783 | HIGH | 8.8 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS … | Jul 27, 2026 |
| CVE-2026-64776 | MEDIUM | 5.5 | The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may … | Jul 27, 2026 |
| CVE-2026-64775 | UNKNOWN | — | A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma … | Jul 27, 2026 |
| CVE-2026-64774 | CRITICAL | 9.8 | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, … | Jul 27, 2026 |
| CVE-2026-64772 | UNKNOWN | — | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe … | Jul 27, 2026 |
| CVE-2026-64771 | CRITICAL | 9.8 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, … | Jul 27, 2026 |
| CVE-2026-64770 | CRITICAL | 9.8 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma … | Jul 27, 2026 |
| CVE-2026-64769 | CRITICAL | 9.8 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma … | Jul 27, 2026 |
| CVE-2026-64768 | HIGH | 8.1 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma … | Jul 27, 2026 |
| CVE-2026-64767 | CRITICAL | 9.8 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote … | Jul 27, 2026 |