Tagged “nvd”
CVEs tagged nvd, newest first.
25608 CVEsRSS
CVE-2026-87116Medium· 6.5Tanium addressed a server-side request forgery vulnerability in Threat Response.
Tanium addressed a server-side request forgery vulnerability in Threat Response.
CVE-2026-87076Medium· 6.5Tanium addressed an information disclosure vulnerability in Discover.
Tanium addressed an information disclosure vulnerability in Discover.
CVE-2026-87024High· 7.2Tanium addressed a SQL injection vulnerability in Asset.
Tanium addressed a SQL injection vulnerability in Asset.
CVE-2026-87113Medium· 6.3Tanium addressed an improper access controls vulnerability in Threat Response.
Tanium addressed an improper access controls vulnerability in Threat Response.
CVE-2026-87105High· 8.8Tanium addressed a SQL injection vulnerability in Threat Response.
Tanium addressed a SQL injection vulnerability in Threat Response.
CVE-2026-92475Medium· 5.3PoCA weakness has been identified in GPAC 26.08-DEV
A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utils/downloader.c. This manipulation of the argument Content-Range causes out-of-bounds read. The attack requires loca…
CVE-2026-88592Critical· 9.1PoCkkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF)
kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file proxy endpoint /getCorsFile is protected by TrustHostFilter against the trust.host whitelist. However, the URL parameter validated by the filt…
CVE-2026-87026Low· 3.8Tanium addressed an improper access controls vulnerability in Threat Response.
Tanium addressed an improper access controls vulnerability in Threat Response.
CVE-2026-86831High· 8.7Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namesp…
Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namesp…
CVE-2026-89083Critical· 9.3HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …
HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …
CVE-2026-89082Critical· 9.3HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …
HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …
CVE-2026-89084High· 8.8HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …
HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …
CVE-2026-92473Low· 3.3PoCA vulnerability was identified in GPAC 26.08-DEV
A vulnerability was identified in GPAC 26.08-DEV. The impacted element is the function gf_sg_command_del of the file src/scenegraph/commands.c of the component BIFS Handler. The manipulation leads to use after free. The attack needs to b…
CVE-2026-86071Low· 3.7Junrar is an open source Java RAR archive library
Junrar is an open source Java RAR archive library. Prior to version 7.6.1, LocalFolderExtractor in src/main/java/com/github/junrar/LocalFolderExtractor.java can create directories outside the intended extraction root when processing a cr…
CVE-2026-73462Medium· 6.5On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected …
On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected …
CVE-2026-63325High· 7.8Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier
Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/respect-core and @redocly/cli, the respect command dynamically evaluates $faker runtime expressions in Arazzo descript…
CVE-2026-63225Medium· 4.4Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier
Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the split command constructs output paths under --outDir from untrusted OpenAPI or AsyncAPI component names and x-codeSample…
CVE-2026-92417Medium· 6.5A vulnerability was found in Open5GS up to 2.8.0
A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the library lib/pfcp/types.c of the component PFCP Handler. The manipulation results in null pointer dereference. The attack…
CVE-2026-63126High· 7.5PoCWire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java
Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire protobuf readers do not consistently validate attacker-controlled lengths against the current logical message boundary b…
CVE-2026-92418Low· 3.5PoCA vulnerability was determined in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd
A vulnerability was determined in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects unknown code of the file src/main/resources/public/js/customerServe/customer.serve.js of the component Save Endp…
CVE-2026-38999High· 7.5PoCA Null Pointer Dereference in the mk_sched_event_close function (mk_server/mk_scheduler.c) of Monkey through commit 4fb0c16 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
A Null Pointer Dereference in the mk_sched_event_close function (mk_server/mk_scheduler.c) of Monkey through commit 4fb0c16 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
CVE-2026-75025Medium· 4.7Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict server-rendered content from accessing local or private network resources
Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict server-rendered content from accessing local or private network resources. Thanks to game0v3r for contributing to this im…
CVE-2026-46352High· 7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, Suricata's IP defragmentation code could deadlock when processing…
CVE-2026-92729High· 8.2PoCSigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler
SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including …
CVE-2026-75516High· 8.7The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.34.0, AMQConnection.start() applies Math.min(maxInboundMessageBodySize, frameMax) after Connection.Tune ne…
CVE-2026-81176Medium· 5.3Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. Prior to 5.9.2, devalue.parse does not reject out-of-bounds indices that are greater than or equal to values.len…
CVE-2026-59823Medium· 5.3LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated LiteLLM Proxy caller with a valid virtual key can place api_base inside the user_config request body to bypass is_req…
CVE-2026-91097Critical· 9.8PoC⚖ disputedHP has identified and remediated multiple externally reported vulnerabilities within HPLIP
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…
CVE-2026-82399High· 7.5PoCCoreDNS is a DNS server written in Go
CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC request paths in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call d…
CVE-2026-68536Critical· 9.8⚖ disputedServer-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affected. Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.
Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affected. Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.