Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
34320
Total
2676
Critical
10130
High
10349
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-42164 | UNKNOWN | — | Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to … | Aug 17, 2026 |
| CVE-2026-42162 | UNKNOWN | — | Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact in a … | Aug 17, 2026 |
| CVE-2026-38165 | UNKNOWN | — | A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a … | Aug 17, 2026 |
| CVE-2026-9859 | MEDIUM | 6.5 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which allows … | Aug 17, 2026 |
| CVE-2026-9816 | HIGH | 8.3 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a … | Aug 17, 2026 |
| CVE-2026-75077 | MEDIUM | 4.3 | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /BSCE2.php. Such … | Aug 17, 2026 |
| CVE-2026-71424 | CRITICAL | 9.6 | Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header … | Aug 17, 2026 |
| CVE-2026-69148 | HIGH | 7.1 | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or … | Aug 17, 2026 |
| CVE-2026-69146 | MEDIUM | 6.5 | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from … | Aug 17, 2026 |
| CVE-2026-67960 | UNKNOWN | — | An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components | Aug 17, 2026 |
| CVE-2026-67918 | UNKNOWN | — | Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in api/hermes/download endpoint | Aug 17, 2026 |
| CVE-2026-67868 | UNKNOWN | — | A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This allows a remote attacker to execute arbitrary code. | Aug 17, 2026 |
| CVE-2026-67854 | UNKNOWN | — | SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code | Aug 17, 2026 |
| CVE-2026-65351 | UNKNOWN | — | This issue was addressed through improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciously crafted web … | Aug 17, 2026 |
| CVE-2026-65349 | UNKNOWN | — | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. An app may … | Aug 17, 2026 |
| CVE-2026-65347 | UNKNOWN | — | The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image may lead … | Aug 17, 2026 |
| CVE-2026-65346 | UNKNOWN | — | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing an image … | Aug 17, 2026 |
| CVE-2026-65343 | UNKNOWN | — | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. A … | Aug 17, 2026 |
| CVE-2026-65341 | UNKNOWN | — | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe … | Aug 17, 2026 |
| CVE-2026-65340 | UNKNOWN | — | This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe … | Aug 17, 2026 |
| CVE-2026-65339 | UNKNOWN | — | A logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. An app may be … | Aug 17, 2026 |
| CVE-2026-65338 | UNKNOWN | — | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe … | Aug 17, 2026 |
| CVE-2026-65337 | UNKNOWN | — | This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe … | Aug 17, 2026 |
| CVE-2026-65336 | UNKNOWN | — | This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe … | Aug 17, 2026 |
| CVE-2026-65335 | UNKNOWN | — | This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe … | Aug 17, 2026 |