Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26391
Total
1955
Critical
7971
High
8223
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-9604 | MEDIUM | 4.3 | A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results … | May 26, 2026 |
| CVE-2026-8680 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | May 26, 2026 |
| CVE-2026-8647 | UNKNOWN | — | Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available. The random_bytes function fell back to using the … | May 26, 2026 |
| CVE-2026-46740 | UNKNOWN | — | Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated … | May 26, 2026 |
| CVE-2026-9603 | MEDIUM | 6.5 | A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of … | May 26, 2026 |
| CVE-2026-9584 | HIGH | 7.3 | A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the component Login. … | May 26, 2026 |
| CVE-2026-5260 | HIGH | 8.2 | A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using … | May 26, 2026 |
| CVE-2026-48710 | MEDIUM | 6.5 | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because … | May 26, 2026 |
| CVE-2026-45574 | HIGH | 8.1 | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the … | May 26, 2026 |
| CVE-2026-45298 | HIGH | 8.6 | Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook … | May 26, 2026 |
| CVE-2026-44985 | UNKNOWN | — | Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: func(r *http.Request) … | May 26, 2026 |
| CVE-2026-44983 | HIGH | 7.3 | smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to 2.6.0, an integer overflow in the internal capacity calculation of smallbitvec can … | May 26, 2026 |
| CVE-2026-44966 | HIGH | 8.3 | Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue … | May 26, 2026 |
| CVE-2026-44905 | HIGH | 7.5 | Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the cryptographic verification pipeline … | May 26, 2026 |
| CVE-2026-44903 | UNKNOWN | — | Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy web UI (enabled … | May 26, 2026 |
| CVE-2026-44900 | HIGH | 8.1 | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.1, in SignedPublicKeysTrustValidatorImpl.isTrusted(), the ECDSA signature verification at line … | May 26, 2026 |
| CVE-2026-44895 | UNKNOWN | — | GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer at … | May 26, 2026 |
| CVE-2026-44788 | MEDIUM | 5.9 | SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47.4 and earlier, a path traversal vulnerability in IArchive.WriteToDirectory() … | May 26, 2026 |
| CVE-2026-44213 | MEDIUM | 6.5 | The OpenTelemetry.Exporter.Instana exports telemetry to Instana backend. Prior to 1.1.0, the OpenTelemetry.Exporter.Instana NuGet package does not validate HTTPS/TLS certificates are valid when sending telemetry to … | May 26, 2026 |
| CVE-2026-43988 | HIGH | 7.5 | Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the ASN.1/OER parsing pipeline … | May 26, 2026 |
| CVE-2026-42015 | MEDIUM | 5.3 | A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write … | May 26, 2026 |
| CVE-2026-42013 | HIGH | 8.2 | A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to … | May 26, 2026 |
| CVE-2026-42012 | HIGH | 7.1 | A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) … | May 26, 2026 |
| CVE-2025-46307 | MEDIUM | 5.5 | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to access sensitive user … | May 26, 2026 |
| CVE-2025-46284 | HIGH | 7.0 | A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to … | May 26, 2026 |