Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28561
Total
2193
Critical
8548
High
8866
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-33317 | HIGH | 8.7 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. In … | Apr 24, 2026 |
| CVE-2026-33208 | UNKNOWN | — | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the /config/ < service > /find-in-config endpoint in … | Apr 24, 2026 |
| CVE-2026-33078 | UNKNOWN | — | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a SQL injection vulnerability in the haproxy_section_save … | Apr 24, 2026 |
| CVE-2026-33077 | UNKNOWN | — | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the oldconfig parameter in the haproxy_section_save interface has … | Apr 24, 2026 |
| CVE-2026-33076 | UNKNOWN | — | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface presents a vulnerability that could … | Apr 24, 2026 |
| CVE-2026-32952 | MEDIUM | 5.3 | go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out … | Apr 24, 2026 |
| CVE-2026-41325 | UNKNOWN | — | Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the … | Apr 24, 2026 |
| CVE-2026-40099 | UNKNOWN | — | Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the … | Apr 24, 2026 |
| CVE-2026-34587 | UNKNOWN | — | Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, Kirby's user permissions control which user role is allowed to perform specific … | Apr 24, 2026 |
| CVE-2026-32870 | UNKNOWN | — | Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `<![CDATA[ ]]>` blocks. If the input value is already valid `CDATA`, … | Apr 24, 2026 |
| CVE-2026-31956 | MEDIUM | 4.3 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to version 4.4.1, any authenticated … | Apr 24, 2026 |
| CVE-2026-31955 | MEDIUM | 4.9 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. An authenticated Server-Side Request Forgery (SSRF) … | Apr 24, 2026 |
| CVE-2026-31953 | MEDIUM | 6.4 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. A stored Cross-Site Scripting (XSS) vulnerability … | Apr 24, 2026 |
| CVE-2026-40630 | CRITICAL | 9.8 | A vulnerability in SenseLive X3050’s web management interface allows unauthorized access to certain configuration endpoints due to improper access control enforcement. An attacker with network … | Apr 24, 2026 |
| CVE-2026-40623 | HIGH | 8.1 | A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameters to be modified without sufficient validation and safety controls. Due … | Apr 24, 2026 |
| CVE-2026-40620 | CRITICAL | 9.8 | A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authentication or authorization on the SenseLive … | Apr 24, 2026 |
| CVE-2026-40431 | MEDIUM | 5.3 | A vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unencrypted HTTP for all administrative communication. Because management traffic, including authentication … | Apr 24, 2026 |
| CVE-2026-39462 | HIGH | 8.1 | A vulnerability exists in SenseLive X3050’s web management interface in which password updates are not reliably applied due to improper handling of credential changes on … | Apr 24, 2026 |
| CVE-2026-35503 | CRITICAL | 9.8 | A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on the client side, relying on hardcoded values within browser-executed … | Apr 24, 2026 |
| CVE-2026-35064 | HIGH | 7.5 | A vulnerability in SenseLive X3050’s management ecosystem allows unauthenticated discovery of deployed units through the vendor’s management protocol, enabling identification of device presence, identifiers, and … | Apr 24, 2026 |
| CVE-2026-31952 | HIGH | 7.6 | Xibo is an open source digital signage platform with a web content management system and Windows display player software. Versions 1.7 through 4.4.0 have an … | Apr 24, 2026 |
| CVE-2026-29197 | MEDIUM | 4.3 | In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/logs and /api/apps/:id/logs have a typo in the required permission check, … | Apr 24, 2026 |
| CVE-2026-29051 | MEDIUM | 4.4 | melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, `melange lint --persist-lint-results` (opt-in flag, also … | Apr 24, 2026 |
| CVE-2026-29050 | MEDIUM | 6.1 | melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, an attacker who can influence a … | Apr 24, 2026 |
| CVE-2026-27843 | CRITICAL | 9.1 | A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be modified without sufficient authentication or server-side validation. By applying … | Apr 24, 2026 |