Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
34320
Total
2676
Critical
10130
High
10349
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-59894 | UNKNOWN | — | sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and output_format='php' … | Aug 17, 2026 |
| CVE-2026-59893 | HIGH | 7.5 | sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted … | Aug 17, 2026 |
| CVE-2026-54284 | UNKNOWN | — | sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed … | Aug 17, 2026 |
| CVE-2026-51346 | CRITICAL | 9.1 | SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensitive information via … | Aug 17, 2026 |
| CVE-2026-50772 | UNKNOWN | — | An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function. | Aug 17, 2026 |
| CVE-2026-50771 | MEDIUM | 6.1 | Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbtirary code via the Email Notification, Create Evaluation Sets … | Aug 17, 2026 |
| CVE-2026-50770 | UNKNOWN | — | An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted request. | Aug 17, 2026 |
| CVE-2026-50769 | UNKNOWN | — | The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conflict endpoint index.php?module=Appointments&action=CheckConflictOfDates&ajaxSkipHeader=true which is used … | Aug 17, 2026 |
| CVE-2026-50768 | CRITICAL | 9.8 | File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the … | Aug 17, 2026 |
| CVE-2026-48053 | MEDIUM | 5.8 | Kolibri is an offline-first education platform. Prior to version 0.19.4, several Kolibri API endpoints accept an unvalidated `baseurl` parameter and fetch attacker-controlled URLs from the … | Aug 17, 2026 |
| CVE-2026-46345 | HIGH | 8.4 | compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing … | Aug 17, 2026 |
| CVE-2026-33437 | HIGH | 8.1 | Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, the Get Info workflow in app/core/src/main/resources/templates/security/get-info-on-pdf.html inserts untrusted … | Aug 17, 2026 |
| CVE-2026-9771 | HIGH | 8.8 | The flash_copy() system call is verified by z_vrfy_flash_copy() in drivers/flash/flash_util.c. On builds with CONFIG_USERSPACE enabled, this handler is the kernel-side trust boundary for a user-mode … | Aug 17, 2026 |
| CVE-2026-68518 | UNKNOWN | — | Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, _sanitize_mustache_dict() in glances/actions.py sanitizes individual Mustache values before chevron.render(), allowing adjacent unescaped Mustache variables … | Aug 17, 2026 |
| CVE-2026-68517 | MEDIUM | 6.5 | Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing … | Aug 17, 2026 |
| CVE-2026-61666 | UNKNOWN | — | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without catching URI::InvalidURIError, … | Aug 17, 2026 |
| CVE-2026-40145 | UNKNOWN | — | A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility and the agent's tamper protection controls. Under certain conditions, the … | Aug 17, 2026 |
| CVE-2026-12630 | MEDIUM | 4.3 | Zephyr's 6LoWPAN IP Header Compression (IPHC) uncompression code contains an out-of-bounds read in get_ihpc_inlined_size() (subsys/net/ip/6lo.c). The destination inline size is looked up in da_inline_size_table, which … | Aug 17, 2026 |
| CVE-2026-12629 | MEDIUM | 4.6 | The ARM PL011 UART driver in drivers/serial/uart_pl011.c fails to acknowledge receive error interrupts. On the PL011, the framing, parity, break, and overrun error interrupts (PL011_IMSC_ERROR_MASK) … | Aug 17, 2026 |
| CVE-2026-12519 | MEDIUM | 5.0 | The WNC-M14A2A LTE-M modem driver mishandles unsolicited %NOTIFYEV: events in on_cmd_socknotifyev() (drivers/modem/vendor_standalone/wncm14a2a.c). The response line is linearized into a fixed 40-byte stack buffer via net_buf_linearize(), … | Aug 17, 2026 |
| CVE-2026-75060 | HIGH | 8.4 | In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools | Aug 17, 2026 |
| CVE-2026-75059 | MEDIUM | 4.4 | In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible | Aug 17, 2026 |
| CVE-2026-75058 | MEDIUM | 5.5 | In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers | Aug 17, 2026 |
| CVE-2026-75057 | MEDIUM | 6.2 | In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log | Aug 17, 2026 |
| CVE-2026-75056 | HIGH | 7.8 | In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible | Aug 17, 2026 |