Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51181
Total
4084
Critical
15175
High
14817
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-64646 | UNKNOWN | — | Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, requests targeting Next.js applications using App … | Jul 27, 2026 |
| CVE-2026-51244 | HIGH | 7.5 | schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in UnpackFrameHeader(). Multiple attacker-controlled index parameters are used to access static and heap table arrays without range … | Jul 27, 2026 |
| CVE-2026-17612 | UNKNOWN | — | Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains an audit log disclosure Vulnerability that could allow an attacker to … | Jul 27, 2026 |
| CVE-2026-16481 | UNKNOWN | — | A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-toolbox. The tool takes an unvalidated pageURL parameter from the … | Jul 27, 2026 |
| CVE-2026-12383 | HIGH | 7.5 | A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access controls (permission_classes=[AllowAny], authentication_classes=[]) and relies solely on the Subject HTTP … | Jul 27, 2026 |
| CVE-2026-10683 | LOW | 2.4 | In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target/slave mode, the rx_full interrupt handler gates the write_requested() callback on dw->state != CMD_SEND, and dw->state … | Jul 27, 2026 |
| CVE-2026-10682 | MEDIUM | 6.6 | The userspace verifier z_vrfy_log_filter_set() for the log_filter_set syscall in subsys/logging/log_mgmt.c performed a signed comparison against the int16_t src_id parameter: src_id < (int16_t)log_src_cnt_get(domain_id). Any negative value … | Jul 27, 2026 |
| CVE-2026-66030 | MEDIUM | 5.4 | Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by … | Jul 27, 2026 |
| CVE-2026-66029 | MEDIUM | 5.4 | Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by … | Jul 27, 2026 |
| CVE-2026-66028 | MEDIUM | 6.7 | Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email … | Jul 27, 2026 |
| CVE-2026-64645 | UNKNOWN | — | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that … | Jul 27, 2026 |
| CVE-2026-64644 | UNKNOWN | — | Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default … | Jul 27, 2026 |
| CVE-2026-64643 | UNKNOWN | — | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server … | Jul 27, 2026 |
| CVE-2026-64642 | UNKNOWN | — | Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using App Router built with … | Jul 27, 2026 |
| CVE-2026-64641 | UNKNOWN | — | Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted requests targeting Next.js applications using … | Jul 27, 2026 |
| CVE-2026-59239 | UNKNOWN | — | Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript … | Jul 27, 2026 |
| CVE-2026-55579 | CRITICAL | 9.8 | Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default password … | Jul 27, 2026 |
| CVE-2026-55578 | HIGH | 8.8 | Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, the terminal feature in Pheditor uses an … | Jul 27, 2026 |
| CVE-2026-54540 | HIGH | 8.8 | Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is an authenticated terminal command whitelist bypass. The terminal … | Jul 27, 2026 |
| CVE-2026-54272 | UNKNOWN | — | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of … | Jul 27, 2026 |
| CVE-2026-51235 | HIGH | 8.8 | LibRaw 0.21 is vulnerable to Buffer Overflow in the stretch() function (src/libraw_cxx.cpp) and fuji_rotate() function (src/decoders/fuji.cpp). | Jul 27, 2026 |
| CVE-2026-48052 | MEDIUM | 5.4 | Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who is a member of any organization can delete … | Jul 27, 2026 |
| CVE-2026-48051 | LOW | 3.5 | Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, Papra's webhook delivery system contains an SSRF protection bypass that allows any … | Jul 27, 2026 |
| CVE-2026-48030 | CRITICAL | 9.9 | Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the … | Jul 27, 2026 |
| CVE-2026-45623 | HIGH | 7.5 | PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In … | Jul 27, 2026 |