Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28433
Total
2190
Critical
8535
High
8856
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-34462 | UNKNOWN | — | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several ProcessServer handlers (KillAllHandler, SuspendAllHandler, and RunSandboxedHandler) copy a WCHAR … | May 05, 2026 |
| CVE-2026-34461 | UNKNOWN | — | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieIniServer RunSbieCtrl handler contains a stack buffer overflow. The … | May 05, 2026 |
| CVE-2026-34459 | UNKNOWN | — | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieSvc proxy service's GetRawInputDeviceInfoSlave handler contains two vulnerabilities that … | May 05, 2026 |
| CVE-2026-34458 | UNKNOWN | — | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI injection vulnerability allows any standard local user to … | May 05, 2026 |
| CVE-2026-34084 | UNKNOWN | — | PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and … | May 05, 2026 |
| CVE-2026-33975 | UNKNOWN | — | Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-server's SecureHttpClientService can be bypassed using … | May 05, 2026 |
| CVE-2026-33489 | UNKNOWN | — | CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza when both a … | May 05, 2026 |
| CVE-2026-33420 | UNKNOWN | — | Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organizations/{org_id}/collections/details) is missing the has_full_access() authorization check that … | May 05, 2026 |
| CVE-2026-33324 | UNKNOWN | — | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to … | May 05, 2026 |
| CVE-2026-33190 | UNKNOWN | — | CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-DNS transports (DoT, DoH, DoH3, … | May 05, 2026 |
| CVE-2026-32936 | UNKNOWN | — | CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and … | May 05, 2026 |
| CVE-2026-32934 | UNKNOWN | — | CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven into unbounded goroutine and memory … | May 05, 2026 |
| CVE-2026-32699 | UNKNOWN | — | FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fails to validate the nick parameter during a POST … | May 05, 2026 |
| CVE-2026-32603 | UNKNOWN | — | Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial of service vulnerability exists in the Sandboxie … | May 05, 2026 |
| CVE-2026-31893 | UNKNOWN | — | Tunnelblick is an open source graphic user interface for OpenVPN on macOS. In versions 3.3beta26 through 9.0beta01, any local user can read arbitrary root-owned files … | May 05, 2026 |
| CVE-2024-52911 | HIGH | 7.5 | Bitcoin Core through 28.x has a security issue, the details of which are not disclosed. The earliest affected version is 0.14. | May 05, 2026 |
| CVE-2026-7855 | HIGH | 8.8 | A vulnerability was detected in D-Link DI-8100 16.07.26A1. Affected by this issue is the function tggl_asp of the file /tggl.asp of the component HTTP Request … | May 05, 2026 |
| CVE-2026-7854 | CRITICAL | 9.8 | A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function url_rule_asp of the file /url_rule.asp of the component … | May 05, 2026 |
| CVE-2026-42997 | HIGH | 7.7 | An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request authorization to be sent to a … | May 05, 2026 |
| CVE-2026-38428 | CRITICAL | 9.8 | Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL … | May 05, 2026 |
| CVE-2026-31835 | UNKNOWN | — | Vaultwarden is a Bitwarden-compatible server written in Rust. In versions 1.35.4 and earlier, the WebAuthn authentication flow in `validate_webauthn_login()` updates persistent credential metadata (1backup_eligible1 and … | May 05, 2026 |
| CVE-2026-30923 | UNKNOWN | — | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsecurity is one component of the ModSecurity v3 … | May 05, 2026 |
| CVE-2026-27960 | CRITICAL | 9.8 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability … | May 05, 2026 |
| CVE-2026-7853 | CRITICAL | 9.8 | A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulation … | May 05, 2026 |
| CVE-2026-7851 | HIGH | 7.2 | A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The manipulation of the argument ID leads to … | May 05, 2026 |