Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
24801
Total
1759
Critical
7594
High
7792
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-45684 | MEDIUM | 4.9 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, OBI's log enricher mishandles writev buffers by … | Jun 02, 2026 |
| CVE-2026-45683 | LOW | 3.8 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Java TLS ioctl probe reads user-controlled ioctl pointers with … | Jun 02, 2026 |
| CVE-2026-45682 | MEDIUM | 5.1 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the custom CappedConcurrentHashMap introduced for Java TLS state tracking never … | Jun 02, 2026 |
| CVE-2026-45681 | MEDIUM | 5.9 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the per-CPU message-buffer fallback path uses a 256-byte backup buffer … | Jun 02, 2026 |
| CVE-2026-45680 | MEDIUM | 5.9 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI replays BPF probe hits into histogram observations by looping … | Jun 02, 2026 |
| CVE-2026-45679 | MEDIUM | 6.5 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI exports raw Redis error text as the span status … | Jun 02, 2026 |
| CVE-2026-45678 | HIGH | 7.5 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol parser assumes BIND message payloads contain a … | Jun 02, 2026 |
| CVE-2026-45676 | MEDIUM | 5.5 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI's replacement ELF parser trusts section offsets, counts, and string … | Jun 02, 2026 |
| CVE-2026-45554 | MEDIUM | 5.3 | NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static assets in NiceGUI accept a sub-path parameter that … | Jun 02, 2026 |
| CVE-2026-45553 | HIGH | 7.5 | NiceGUI is a Python-based UI framework. Prior to version 3.12.0, ui.restructured_text() renders reStructuredText server-side with Docutils without disabling file insertion directives. When a NiceGUI application … | Jun 02, 2026 |
| CVE-2026-45080 | UNKNOWN | — | Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, improper access control allows disclosure of password hash. This issue has been … | Jun 02, 2026 |
| CVE-2026-44367 | LOW | 2.7 | Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, a vulnerability exists in the user registration and login mechanisms due to … | Jun 02, 2026 |
| CVE-2026-42654 | HIGH | 7.1 | Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows Password Recovery Exploitation. This issue affects Wallet System … | Jun 02, 2026 |
| CVE-2026-40780 | HIGH | 7.5 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Liquid Web / StellarWP BookIt allows Password Recovery Exploitation. This issue affects BookIt: from n/a … | Jun 02, 2026 |
| CVE-2026-40619 | HIGH | 7.8 | A high security vulnerability affecting Security Center main server installations has been identified. It could allow an attacker with local OS privileges to the main … | Jun 02, 2026 |
| CVE-2026-38978 | UNKNOWN | — | transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths. | Jun 02, 2026 |
| CVE-2026-35718 | UNKNOWN | — | A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers to read any file on the device via … | Jun 02, 2026 |
| CVE-2026-35716 | UNKNOWN | — | A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via an … | Jun 02, 2026 |
| CVE-2026-34460 | MEDIUM | 5.4 | NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callback handling does not validate the state parameter server-side before exchanging … | Jun 02, 2026 |
| CVE-2026-33398 | UNKNOWN | — | NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/pages/forum/get_quotes.php` only checks whether the caller is logged in, then reads a post by attacker-controlled … | Jun 02, 2026 |
| CVE-2026-30652 | UNKNOWN | — | A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows … | Jun 02, 2026 |
| CVE-2026-30650 | UNKNOWN | — | A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw … | Jun 02, 2026 |
| CVE-2026-30649 | UNKNOWN | — | Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via the set_getparam.cgi component | Jun 02, 2026 |
| CVE-2026-10629 | CRITICAL | 9.1 | SIP signaling stack in Verizon IMS (unspecified version) implements SIP signaling without IPsec integrity protection (missing Security-Client/Security-Server headers and ESP traffic), which allows an on-path … | Jun 02, 2026 |
| CVE-2026-10591 | HIGH | 8.8 | Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands … | Jun 02, 2026 |