Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26391
Total
1955
Critical
7971
High
8223
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-7452 | HIGH | 7.8 | A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to … | May 26, 2026 |
| CVE-2026-7451 | HIGH | 7.8 | A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to … | May 26, 2026 |
| CVE-2026-7450 | MEDIUM | 5.3 | A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to … | May 26, 2026 |
| CVE-2026-7251 | CRITICAL | 9.8 | Eppendorf BioFlo 320 is vulnerable to due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo … | May 26, 2026 |
| CVE-2026-48696 | MEDIUM | 6.2 | FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different vulnerability than CVE-2026-48686 and CVE-2026-48689. | May 26, 2026 |
| CVE-2026-48695 | HIGH | 8.1 | FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php (lines 107-108) constructs … | May 26, 2026 |
| CVE-2026-48694 | HIGH | 8.1 | FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integration plugin. In src/juniper_plugin/fastnetmon_juniper.php, the $IP_ATTACK variable (received from argv[1]) is … | May 26, 2026 |
| CVE-2026-47202 | UNKNOWN | — | Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to request a … | May 26, 2026 |
| CVE-2026-46624 | CRITICAL | 9.9 | Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL … | May 26, 2026 |
| CVE-2026-44776 | UNKNOWN | — | Kavita is a cross platform reading server. Prior to 0.9.0, the download, size-check, and chapter metadata endpoints do not enforce library-level authorization. A low-privileged user … | May 26, 2026 |
| CVE-2026-44775 | UNKNOWN | — | Kavita is a cross platform reading server. Prior to 0.9.0, the ReaderController.GetImage endpoint is decorated with [AllowAnonymous], allowing completely unauthenticated access to page images from … | May 26, 2026 |
| CVE-2026-44749 | MEDIUM | 4.3 | The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI … | May 26, 2026 |
| CVE-2026-44730 | HIGH | 7.2 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.7, an organization admin can escalate their privileges by … | May 26, 2026 |
| CVE-2026-44728 | HIGH | 8.2 | Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted … | May 26, 2026 |
| CVE-2026-44707 | MEDIUM | 6.8 | Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentication flow. Because email confirmation was … | May 26, 2026 |
| CVE-2026-44706 | HIGH | 8.5 | Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection vulnerability exists in the conversation and contact filter APIs. When filtering … | May 26, 2026 |
| CVE-2026-44669 | HIGH | 8.7 | FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in assessment … | May 26, 2026 |
| CVE-2026-44668 | CRITICAL | 9.8 | FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invoke() without checking … | May 26, 2026 |
| CVE-2026-44667 | HIGH | 8.7 | FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in remediation … | May 26, 2026 |
| CVE-2026-42448 | LOW | 3.5 | Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. Prior to 0.24.0, there is a path traversal when … | May 26, 2026 |
| CVE-2026-41164 | MEDIUM | 4.4 | nuts-node is the reference implementation of the Nuts specification. Prior to 6.2.3 and 5.4.31, the v1 access token introspection endpoint (/auth/v1/introspect_access_token) accepts any JWT signed … | May 26, 2026 |
| CVE-2026-24201 | MEDIUM | 5.8 | NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause an out-of-bound access. A successful exploit of this vulnerability … | May 26, 2026 |
| CVE-2026-24200 | HIGH | 7.0 | NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free for stack memory. A successful exploit of … | May 26, 2026 |
| CVE-2026-24199 | MEDIUM | 4.7 | NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where a user could cause a race condition by reordering compiler or processor … | May 26, 2026 |
| CVE-2026-24198 | MEDIUM | 5.6 | NVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memory, which might cause … | May 26, 2026 |