Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

24801
Total
1759
Critical
7594
High
7792
Medium
CVE ID Severity Score Description Published
CVE-2026-45684 MEDIUM 4.9 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, OBI's log enricher mishandles writev buffers by … Jun 02, 2026
CVE-2026-45683 LOW 3.8 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Java TLS ioctl probe reads user-controlled ioctl pointers with … Jun 02, 2026
CVE-2026-45682 MEDIUM 5.1 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the custom CappedConcurrentHashMap introduced for Java TLS state tracking never … Jun 02, 2026
CVE-2026-45681 MEDIUM 5.9 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the per-CPU message-buffer fallback path uses a 256-byte backup buffer … Jun 02, 2026
CVE-2026-45680 MEDIUM 5.9 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI replays BPF probe hits into histogram observations by looping … Jun 02, 2026
CVE-2026-45679 MEDIUM 6.5 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI exports raw Redis error text as the span status … Jun 02, 2026
CVE-2026-45678 HIGH 7.5 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol parser assumes BIND message payloads contain a … Jun 02, 2026
CVE-2026-45676 MEDIUM 5.5 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI's replacement ELF parser trusts section offsets, counts, and string … Jun 02, 2026
CVE-2026-45554 MEDIUM 5.3 NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static assets in NiceGUI accept a sub-path parameter that … Jun 02, 2026
CVE-2026-45553 HIGH 7.5 NiceGUI is a Python-based UI framework. Prior to version 3.12.0, ui.restructured_text() renders reStructuredText server-side with Docutils without disabling file insertion directives. When a NiceGUI application … Jun 02, 2026
CVE-2026-45080 UNKNOWN Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, improper access control allows disclosure of password hash. This issue has been … Jun 02, 2026
CVE-2026-44367 LOW 2.7 Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, a vulnerability exists in the user registration and login mechanisms due to … Jun 02, 2026
CVE-2026-42654 HIGH 7.1 Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows Password Recovery Exploitation. This issue affects Wallet System … Jun 02, 2026
CVE-2026-40780 HIGH 7.5 Authentication Bypass Using an Alternate Path or Channel vulnerability in Liquid Web / StellarWP BookIt allows Password Recovery Exploitation. This issue affects BookIt: from n/a … Jun 02, 2026
CVE-2026-40619 HIGH 7.8 A high security vulnerability affecting Security Center main server installations has been identified. It could allow an attacker with local OS privileges to the main … Jun 02, 2026
CVE-2026-38978 UNKNOWN transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths. Jun 02, 2026
CVE-2026-35718 UNKNOWN A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allows authenticated attackers to read any file on the device via … Jun 02, 2026
CVE-2026-35716 UNKNOWN A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authenticated remote attackers to execute arbitrary code as root via an … Jun 02, 2026
CVE-2026-34460 MEDIUM 5.4 NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callback handling does not validate the state parameter server-side before exchanging … Jun 02, 2026
CVE-2026-33398 UNKNOWN NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/pages/forum/get_quotes.php` only checks whether the caller is logged in, then reads a post by attacker-controlled … Jun 02, 2026
CVE-2026-30652 UNKNOWN A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw allows … Jun 02, 2026
CVE-2026-30650 UNKNOWN A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a. This flaw … Jun 02, 2026
CVE-2026-30649 UNKNOWN Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via the set_getparam.cgi component Jun 02, 2026
CVE-2026-10629 CRITICAL 9.1 SIP signaling stack in Verizon IMS (unspecified version) implements SIP signaling without IPsec integrity protection (missing Security-Client/Security-Server headers and ESP traffic), which allows an on-path … Jun 02, 2026
CVE-2026-10591 HIGH 8.8 Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands … Jun 02, 2026