Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26383
Total
1955
Critical
7969
High
8219
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-8363 | CRITICAL | 9.8 | A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path starting with /resources: | May 27, 2026 |
| CVE-2026-8362 | CRITICAL | 9.8 | A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with /woshome | May 27, 2026 |
| CVE-2026-8361 | HIGH | 7.5 | A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome | May 27, 2026 |
| CVE-2026-8360 | HIGH | 7.5 | Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWebDavModule.dll) can return a NULL pointer (i.e., when no user is logged into the Triofox Server … | May 27, 2026 |
| CVE-2026-8359 | HIGH | 7.5 | When processing a request with a URL path starting with /status or /sysinfo, WOSHttpStatusModule.dll is to be loaded to handle such URL patterns. The WOSBin_LoadHttpModule … | May 27, 2026 |
| CVE-2026-49009 | LOW | 3.1 | Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal. | May 27, 2026 |
| CVE-2026-48792 | MEDIUM | 4.4 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/evdev.c silently ignores EACCES errors when opening /dev/input/event* nodes, causing pusb_has_virtual_input_device() to … | May 27, 2026 |
| CVE-2026-48066 | MEDIUM | 5.7 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/log.c contains a process-wide static pointer that is written on every PAM … | May 27, 2026 |
| CVE-2026-48065 | MEDIUM | 6.7 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/conf.c allocates heap memory proportional to n_devices, a count derived from libxml2 … | May 27, 2026 |
| CVE-2026-48064 | HIGH | 8.1 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, when a PAM service is configured with deny_remote=false in pam_usb (commonly done … | May 27, 2026 |
| CVE-2026-47274 | MEDIUM | 6.3 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, multiple pam_usb helper tools resolved external binaries through the PATH environment variable … | May 27, 2026 |
| CVE-2026-47273 | MEDIUM | 6.5 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb builds XPath expressions from user-supplied identifiers (PAM username, service name) and … | May 27, 2026 |
| CVE-2026-47272 | HIGH | 7.1 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, the pusb_pad_compare() function in src/pad.c only verified that the user-side pad (~/.pamusb/device.pad) … | May 27, 2026 |
| CVE-2026-47271 | MEDIUM | 5.1 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, src/mem.c implemented out-of-memory guards for xmalloc(), xrealloc(), and xstrdup() using assert(data != … | May 27, 2026 |
| CVE-2026-47161 | UNKNOWN | — | RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configures its Celery workers to accept and deserialize untrusted 'pickle' data. An attacker … | May 27, 2026 |
| CVE-2026-45134 | HIGH | 7.1 | LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull … | May 27, 2026 |
| CVE-2026-45108 | HIGH | 8.4 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 2.0.0 to before 3.1.5 and 2.3.11, Himmelblau contained an authentication bypass vulnerability … | May 27, 2026 |
| CVE-2026-45104 | HIGH | 7.5 | MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always calls _SLDApplyRuleValues(psRule, psLayer, 1); for any <Rule> carrying <ElseFilter/> … | May 27, 2026 |
| CVE-2026-45102 | CRITICAL | 9.9 | OneUptime is an open-source monitoring and observability platform. Prior to 10.0.98, OneUptime uses the Node.js' vm module as an isolation primitive. This API was not … | May 27, 2026 |
| CVE-2026-44888 | CRITICAL | 9.8 | Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's SaveConfigFile() endpoint writes user-supplied numeric config values (e.g., SMTP_PORT) … | May 27, 2026 |
| CVE-2026-44887 | CRITICAL | 9.8 | Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's web-based configuration editor allows arbitrary Python code to be … | May 27, 2026 |
| CVE-2026-44886 | UNKNOWN | — | Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. From 2024-06-29 to before 2026-05-07, the web application endpoint is vulnerable to SQL … | May 27, 2026 |
| CVE-2026-44724 | HIGH | 7.8 | systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when … | May 27, 2026 |
| CVE-2026-44681 | MEDIUM | 6.1 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and … | May 27, 2026 |
| CVE-2026-44590 | CRITICAL | 9.3 | Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via … | May 27, 2026 |