Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25592
Total
1903
Critical
7807
High
8024
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-44518 | MEDIUM | 5.3 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS … | May 29, 2026 |
| CVE-2026-42951 | MEDIUM | 5.4 | An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes. | May 29, 2026 |
| CVE-2026-42941 | HIGH | 8.3 | The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change. | May 29, 2026 |
| CVE-2026-42929 | HIGH | 8.3 | Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials. | May 29, 2026 |
| CVE-2026-40425 | MEDIUM | 5.7 | The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password. | May 29, 2026 |
| CVE-2026-7786 | CRITICAL | 9.8 | Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credentials embedded in the firmware image. These credentials can … | May 29, 2026 |
| CVE-2026-6824 | HIGH | 8.4 | A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers … | May 29, 2026 |
| CVE-2026-5768 | HIGH | 8.8 | The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range … | May 29, 2026 |
| CVE-2026-5386 | CRITICAL | 9.1 | The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password … | May 29, 2026 |
| CVE-2026-47179 | HIGH | 7.7 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns the contents of any Docker Compose include directive … | May 29, 2026 |
| CVE-2026-47125 | HIGH | 8.8 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/environments/{id}/templates/variables endpoint, which writes the system-wide .env.global file … | May 29, 2026 |
| CVE-2026-45668 | UNKNOWN | — | Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malicious ZIP archive imported with … | May 29, 2026 |
| CVE-2026-45661 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows … | May 29, 2026 |
| CVE-2026-45660 | MEDIUM | 5.4 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image proxy's URL validation could be bypassed … | May 29, 2026 |
| CVE-2026-45633 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. … | May 29, 2026 |
| CVE-2026-45632 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, … | May 29, 2026 |
| CVE-2026-45631 | CRITICAL | 10.0 | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SECRET fallback ("better-auth-secret-123456789") lets an unauthenticated attacker forge … | May 29, 2026 |
| CVE-2026-45630 | CRITICAL | 9.0 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner … | May 29, 2026 |
| CVE-2026-45629 | CRITICAL | 9.9 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any … | May 29, 2026 |
| CVE-2026-45628 | CRITICAL | 9.6 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands using JavaScript template literals and executes them … | May 29, 2026 |
| CVE-2026-45627 | HIGH | 8.2 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query … | May 29, 2026 |
| CVE-2026-45626 | MEDIUM | 6.3 | Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /environments/{id}/volumes/{volumeName}/browse accepts a path query parameter that is … | May 29, 2026 |
| CVE-2026-45625 | CRITICAL | 9.9 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-based REST API exposes nine endpoints under /api/customize/git-repositories and … | May 29, 2026 |
| CVE-2026-45577 | UNKNOWN | — | Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app … | May 29, 2026 |
| CVE-2026-44697 | HIGH | 8.6 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any peer that … | May 29, 2026 |