Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
34320
Total
2676
Critical
10130
High
10349
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-34399 | HIGH | 7.8 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCAD's BIM Workbench contains an eval() call on untrusted data from … | Aug 17, 2026 |
| CVE-2026-34398 | HIGH | 7.8 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mod/BIM/bimcommands/BimProjectManager.py in the BIM Project Manager Load Template flow passes attacker-controlled … | Aug 17, 2026 |
| CVE-2026-19589 | HIGH | 7.1 | Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system modification and could lead to … | Aug 17, 2026 |
| CVE-2026-75014 | HIGH | 7.3 | A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/get_barcode_data.php. This manipulation of the … | Aug 17, 2026 |
| CVE-2026-75013 | MEDIUM | 6.5 | A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation results in null pointer dereference. The … | Aug 17, 2026 |
| CVE-2026-75012 | MEDIUM | 6.5 | A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by this issue is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component … | Aug 17, 2026 |
| CVE-2026-74234 | HIGH | 7.7 | Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaScript execution in a victim's browser by embedding a Mermaid block … | Aug 17, 2026 |
| CVE-2026-71858 | UNKNOWN | — | Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attacker-controlled shortcuts.xml bypass the HMAC validation applied to UserDefinedCommands … | Aug 17, 2026 |
| CVE-2026-71553 | UNKNOWN | — | ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id accepts the inherited path toString.call and passes it through the utility … | Aug 17, 2026 |
| CVE-2026-71486 | MEDIUM | 4.3 | vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/derender endpoints accept caller-supplied GenerateResponse objects whose generate_responses, … | Aug 17, 2026 |
| CVE-2026-71472 | CRITICAL | 9.1 | A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to … | Aug 17, 2026 |
| CVE-2026-70495 | HIGH | 8.8 | A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If … | Aug 17, 2026 |
| CVE-2026-68005 | HIGH | 7.5 | An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in … | Aug 17, 2026 |
| CVE-2026-68004 | UNKNOWN | — | An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), … | Aug 17, 2026 |
| CVE-2026-67678 | UNKNOWN | — | File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code | Aug 17, 2026 |
| CVE-2026-63670 | MEDIUM | 6.1 | ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packages/sanitize-html/index.js when textarea or xmp is included … | Aug 17, 2026 |
| CVE-2026-63669 | MEDIUM | 6.5 | ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the destination parent's _create permission because … | Aug 17, 2026 |
| CVE-2026-63667 | MEDIUM | 6.5 | ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export module in packages/import-export/lib/formats/gzip.js constructs an attachment source path from the attacker-controlled _id, … | Aug 17, 2026 |
| CVE-2026-57485 | HIGH | 8.5 | Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /api/v1/pipeline/handleData endpoint in app/core/src/main/java/stirling/software/SPDF/controller/api/pipeline/PipelineProcessor.java injects the STIRLING-PDF-BACKEND-API-USER … | Aug 17, 2026 |
| CVE-2026-57233 | HIGH | 8.1 | Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress function joins untrusted ZIP entry names to unzipDestTo without canonical … | Aug 17, 2026 |
| CVE-2026-54758 | HIGH | 7.8 | Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the expandNppEnvironmentStrs function in PowerEditor/src/WinControls/StaticDialog/RunDlg/RunDlg.cpp copies a Notepad++ variable name between $( and … | Aug 17, 2026 |
| CVE-2026-52886 | UNKNOWN | — | Notepad++ is a free and open-source source code editor. Prior to 8.9.7, Notepad++ validates the backupFilePath attribute from session.xml with std::wstring::starts_with against the expected backup … | Aug 17, 2026 |
| CVE-2026-19650 | HIGH | 7.1 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 … | Aug 17, 2026 |
| CVE-2026-19478 | CRITICAL | 9.4 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 … | Aug 17, 2026 |
| CVE-2026-75011 | MEDIUM | 6.3 | A flaw has been found in kylecui NetForensicMCP 2.1.0. Impacted is the function execAsync of the file index.js. Executing a manipulation of the argument interface/protocol … | Aug 17, 2026 |