Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26395
Total
1955
Critical
7973
High
8225
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-44502 | MEDIUM | 4.3 | Bugsink is a self-hosted error tracking tool. Prior to 2.1.3, Bugsink’s webhook URL validation could be (partially) bypassed because of a mismatch in URL parsing. … | May 26, 2026 |
| CVE-2026-44314 | MEDIUM | 4.3 | Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device only through Condition.Permission(User.class, getUserId(), Device.class) and then immediately streams … | May 26, 2026 |
| CVE-2026-43982 | UNKNOWN | — | Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploadedFileSaveIn() in lua/upload/upload.go uses filepath.Join() with the caller-supplied directory but performs no boundary check … | May 26, 2026 |
| CVE-2026-43981 | UNKNOWN | — | Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engine/luahandler.go, the sync.RWMutex protecting LoadCommonFunctions is released before L.Push() and L.PCall() execute. Since … | May 26, 2026 |
| CVE-2026-40384 | UNKNOWN | — | An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability. | May 26, 2026 |
| CVE-2026-40383 | CRITICAL | 9.8 | An improper validation of user-supplied input leads to a local file inclusion vulnerability. | May 26, 2026 |
| CVE-2026-35223 | UNKNOWN | — | An improper access check allows unauthorized access to com_config webservice endpoints. | May 26, 2026 |
| CVE-2026-35222 | CRITICAL | 9.8 | Improperly validated order clauses lead to a SQL injection vulnerability in com_tags. | May 26, 2026 |
| CVE-2026-35221 | CRITICAL | 9.8 | Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder. | May 26, 2026 |
| CVE-2026-35220 | MEDIUM | 4.3 | Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users. | May 26, 2026 |
| CVE-2026-30895 | MEDIUM | 6.1 | Lack of output escaping leads to a XSS vector in the readmore links for com_content. | May 26, 2026 |
| CVE-2026-30894 | MEDIUM | 6.1 | Lack of output escaping leads to a XSS vector in the content history component. | May 26, 2026 |
| CVE-2026-2264 | UNKNOWN | — | A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens. For … | May 26, 2026 |
| CVE-2026-25901 | MEDIUM | 6.1 | Lack of output escaping leads to a XSS vector in the multilingual associations component. | May 26, 2026 |
| CVE-2026-25900 | MEDIUM | 6.1 | Lack of output escaping leads to a XSS vector in the feed modules. | May 26, 2026 |
| CVE-2026-24212 | HIGH | 7.5 | NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to … | May 26, 2026 |
| CVE-2026-24162 | HIGH | 7.8 | NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead … | May 26, 2026 |
| CVE-2025-36221 | MEDIUM | 5.3 | IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from … | May 26, 2026 |
| CVE-2025-36220 | MEDIUM | 4.3 | IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A … | May 26, 2026 |
| CVE-2025-36148 | MEDIUM | 5.4 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerable to cross-site scripting. This vulnerability allows … | May 26, 2026 |
| CVE-2025-36145 | MEDIUM | 5.4 | IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files … | May 26, 2026 |
| CVE-2025-36126 | MEDIUM | 6.4 | IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. … | May 26, 2026 |
| CVE-2025-14290 | MEDIUM | 5.4 | IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vulnerable to server-side request forgery (SSRF). This may allow … | May 26, 2026 |
| CVE-2025-13755 | MEDIUM | 5.5 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files … | May 26, 2026 |
| CVE-2026-48692 | HIGH | 8.1 | FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with grpc::InsecureServerCredentials() (src/fastnetmon.cpp line … | May 26, 2026 |