Newest CVEs

IDDescriptionSeverityUpdated
CVE-2026-6502Debian Linux - qemu - None Ubuntu Linux - [Unknown description]
low
CVE-2026-6425Debian Linux - qemu - None Ubuntu Linux - [Unknown description]
low
CVE-2026-55556Debian Linux - rsyslog - None Ubuntu Linux - [Unknown description]
high
CVE-2026-55483Snipe-IT Vulnerable to Privilege Escalation via Missing admin Permission Check in User Creation
high
CVE-2026-48915Debian Linux - qemu - None Ubuntu Linux - [Unknown description]
low
CVE-2026-48004Debian Linux - qemu - None Ubuntu Linux - [Unknown description]
low
CVE-2026-41440Debian Linux - qemu - None Ubuntu Linux - [Unknown description]
low
CVE-2026-41439Debian Linux - qemu - None Ubuntu Linux - [Unknown description]
low
CVE-2026-41438Debian Linux - qemu - None Ubuntu Linux - [Unknown description]
low
CVE-2026-41437Debian Linux - qemu - None Ubuntu Linux - [Unknown description]
low
CVE-2026-41436Debian Linux - qemu - None Ubuntu Linux - [Unknown description]
low
CVE-2026-41435Debian Linux - qemu - None Ubuntu Linux - [Unknown description]
low
CVE-2026-3886A design error vulnerability has been identified in QEMU. This issue affects the virtio-gpu driver.
high
CVE-2025-55662Debian Linux - gpac - None
medium
CVE-2016-82007Microsoft Windows DNS server can be configured to respond to inverse queries when HKLM\\System\\CurrentControlSet\\Services\\DNS\\Parameters\\EnableIQueryResponseGeneration (REG_DWORD) is set to a non-zero value. By default this registry setting is missing and the DNS server returns a "Not Implemented" error for an inverse query. However, if inverse query response generation is enabled, there is a buffer over-read issue in dns.exe!answerIQuery(). Inside the function, Dns_ReadRecordStructureFromPacket() is called to parse a Resource Record (RR) inside the inverse query packet. That function returns a pointer to a location immediately followed by the end of the RR. This location is the end of the query packet. Later, a strlen() operation is performed. If the length of the string is not greater than 16, the string is then copied to a local stack buffer, which will become the QNAME (enclosed with open and close brackets) in the question section of the inverse query response. If the length of the string is greater than 16, an error message of return code 1 (Format Error) is returned. The issues of performing a strlen() operation at the end of the inverse query packet may have different impacts: Data at the end of the packet can be non-zero up until a non-accessible page is reached. This can cause an access violation leading to a remote denial of service. Data at the end of the packet can be returned to the client if its 'strlen' is less than or equal to 16 bytes. This may result in a remote information disclosure issue.
medium
CVE-2016-820001 - CVE-2016-82000 - Two fields in the 'Host Details' section of a scan did not properly sanitize input. By importing a malicious file or scanning a compromised host returning JavaScript instead of a hostname, an attacker could introduce JavaScript that would be stored in the scan results, which could be in turn be executed within the context of the user viewing the results. Note that this issue goes back to the Nessus UI version 2.0.0. CVSSv2 Base/Temporal: 2.6 / 2.1 (AV:N/AC:H/Au:N/C:N/I:P/A:N/E:F/RL:OF/RC:C) #2 - CVE-2016-82001 - When scanning a Mac OS X host using credentials, a malicious local user could trick Nessus into executing an arbitrary command as root, thus resulting into a privilege-escalation vulnerability. Note that the following CVSSv2 score reflects the risk to the host being scanned by Nessus, not the system hosting Nessus. Since Nessus is being used as an exploit for a target host, the score does not reflect a threat to Nessus. As such, it is not being listed as the primary CVSSv2 score for this advisory. CVSSv2 Base/Temporal: 7.6 / 4.9 (AV:N/AC:H/Au:N/C:C/I:C/A:C/E:POC/RL:OF/RC:C) #3 Nessus Folder Name Stored Scripting Charlie Svensson reported that Nessus will render script code for folder names. This was also found internally but filed as a regular bug, as the folder names only render to the user who renamed them. Since folder names are not seen across user accounts, this does not pose any risk. Regardless, this issue has been fixed. Please note that Tenable strongly recommends that Nessus be installed on a subnet that is not Internet addressable. Tenable has released version 6.5.5 that corresponds to the supported operating systems and architectures, which is not affected. To update your Nessus installation, follow these steps: Download the appropriate installation file to the system hosting Nessus or Nessus Enterprise, available at the Tenable Support Portal (https://support.tenable.com/support-center/index.php?x=&mod_id=200) Stop the Nessus service. Install according to your operating system procedures. Restart the Nessus service.
medium
CVE-2015-82001ManageEngine Desktop Central contains a flaw that may allow an unauthenticated attacker to execute remote code. The vulnerability is due to the 'applicationName' parameter not being sanitized, and the fact that the 'fileName' parameter can be constructed such that it can pass various checks but still end up with a .JSP extension. The following example shows the output: [mamort@park]$ nasl -WaXt 192.168.0.99 medc_fileupload_rce_91082.nasl Nessus was able to exploit the issue using the following requests : ------------------------------ Request #1------------------------------ POST /statusUpdate?actionToCall=3&actions=2&domainName=Nessus_dom&customerId=1&configDataID=1&computerName=db-dev&applicationName=../../../../../&fileName=medc_fileupload_rce_91082.jsp%00.log HTTP/1.1 Host: 192.168.0.99:8020 Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1 Accept-Language: en Content-Type: text/html Connection: Keep-Alive Content-Length: 383 User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Pragma: no-cache Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, / ------------------------------ Request #2------------------------------ GET /medc_fileupload_rce_91082.jsp HTTP/1.1 Host: 192.168.0.99:8020 Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1 Accept-Language: en Connection: Keep-Alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) Pragma: no-cache Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, /
critical
CVE-2014-8274No description available
medium
CVE-2014-4879No description available
medium
CVE-2014-4878No description available
medium
CVE-2014-4704No description available
medium
CVE-2014-2961No description available
medium
CVE-2012-5944No description available
medium
CVE-2011-4027No description available
high
CVE-2011-3485No description available
medium
CVE-2005-0154No description available
high
CVE-2005-0153No description available
medium
CVE-2005-0132No description available
medium
CVE-2026-55787flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf
high
CVE-2026-48316ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
critical
2026-07-09
CVE-2026-43825Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected: before 3.0.0-M4 (libsvm document categorization module; introduced in OPENNLP-1808 and only present on the 3.x line) Description: SvmDoccatModel.deserialize(InputStream) reads an attacker-controlled stream with java.io.ObjectInputStream and calls readObject() without an ObjectInputFilter installed. ObjectInputStream materialises every class referenced in the stream before the resulting object is cast to SvmDoccatModel, so the cast that follows readObject() executes only after the foreign object graph has already been deserialised in full. If a Java deserialization gadget chain is available on the consumer's classpath, a crafted payload supplied to deserialize() executes arbitrary code in the JVM that loads it. Apache OpenNLP itself does not ship a known gadget chain, so the realistic risk is to downstream applications that embed the libsvm module alongside vulnerable transitive dependencies. The method is public and static, so any caller can pass an untrusted stream to it directly. The practical impact is remote code execution against processes that load SvmDoccatModel instances from untrusted or semi-trusted origins. Mitigation: 3.x users should upgrade to 3.0.0-M4. Users who cannot upgrade immediately should treat all serialized SvmDoccatModel streams as untrusted input unless their provenance is verified, and should avoid invoking SvmDoccatModel.deserialize() on streams supplied by end users or fetched from third-party sources without integrity checks.
high
2026-07-08
CVE-2026-40257OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.21.0 and prior to version 4.11.0, the ARM Crypto Extensions accelerated SHA-3 implementation has an off-by-one error that can cause a massive heap overflow that corrupts all TEE kernel memory following the hash state. This affects all platforms built with `CFG_CRYPTO_WITH_CE82=y` (ARMv8.2+ with SHA3 Crypto Extensions). Version 4.11.0 contains a patch. As a workaround, disable SHA3 Crypto Extensions with `CFG_CRYPTO_WITH_CE82=n`.
medium
2026-07-07
CVE-2026-40141A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts with specific permissions.
high
2026-07-07
CVE-2026-40140BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of client-supplied input may allow an unauthenticated remote attacker to trigger a denial-of-service condition affecting appliance availability.
high
2026-07-07
CVE-2026-40139A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled.
critical
2026-07-07
CVE-2026-40138A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled
critical
2026-07-07
CVE-2025-53831DrawIO for ownCloud is an application for using DrawIO with the file storage, synchronization, and sharing application ownCloud Classic. In DrawIO for ownCloud prior to version 1.0.2, which corresponds to ownCloud 10 prior to version 10.15.3, attackers with access to the DrawIO app can leverage improper neutralization of input during web page generation to achieve stored XSS. Upgrade ownCloud 10 to version 10.15.3 or later or upgrade DrawIO for ownCloud 10 to version 1.0.2 or later to receive a patch.
high
2026-07-06
CVE-2026-49439OpenRemote read-only asset users can write predicted datapoints
medium
CVE-2026-52889Formie Hidden field defaults vulnerable to Server-Side Template Injection
critical
CVE-2026-5268An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated attacker to bypass security controls and gain unauthorized access to the underlying filesystem. Successful exploitation could allow an attacker to read or modify system files.
critical
2026-07-08
CVE-2026-59196pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules directory. Traversal aliases could escape that directory, while reserved aliases such as .bin or .pnpm could overwrite pnpm-owned layout. This vulnerability is fixed in 10.34.4 and 11.7.0.
high
2026-07-07
CVE-2026-59195pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies section and uses those names directly when creating config dependency symlinks under node_modules/.pnpm-config. A malicious repository can commit a crafted pnpm-lock.yaml whose env-lockfile document contains a traversal-shaped config dependency name. During pnpm install, pnpm installs the config dependency and creates a symlink at a path derived from that name. This vulnerability is fixed in 10.34.4 and 11.8.0.
high
2026-07-07
CVE-2026-59194pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm patch-remove to delete an arbitrary reachable file. This vulnerability is fixed in 10.34.4 and 11.7.0.
high
2026-07-07
CVE-2026-59152LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can send an HTTP request to a server running the LangSmith SDK's TracingMiddleware can cause that server to read an arbitrary file from its local filesystem and upload the contents to LangSmith as a trace attachment. Depending on how the distributed trace system is deployed, triggering a read may not require authentication. Retrieving the contents requires read access to the LangSmith workspace the traces are sent to. The net effect is a trust-boundary crossing: a party with workspace trace-read access (for example a low-privilege workspace member, a contractor, or a compromised teammate account) gains the ability to read files from any server running TracingMiddleware, a capability outside that workspace's intended trust boundary. This vulnerability is fixed in 0.8.18.
medium
2026-07-07
CVE-2026-58203pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource reads secret values from files in a configured secrets_dir. When secrets_nested_subdir=True, a directory entry inside secrets_dir that is a symbolic link pointing outside secrets_dir is followed, so files outside the configured directory are read into settings values. The same code path bypasses the documented secrets_dir_max_size protection. An attacker or lower-privileged component able to influence entries in the configured secrets directory (for example, a writable or shared secrets mount) can turn this into an unintended local file read into settings and can defeat the advertised loading-size cap. This vulnerability is fixed in 2.14.2.
medium
2026-07-09
CVE-2026-13122OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled
medium
2026-07-09
CVE-2025-53830Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud. Versions of Anti-Virus for ownCloud before 1.2.3 are vulnerable to Server-Side Request Forgery (SSRF). This corresponds to versions of ownCloud 10 prior to 10.15.3. Upgrade ownCloud 10 to version 10.15.3 or later or upgrade Anti-Virus for ownCloud 10 to version 1.2.3 or later to receive a fix.
critical
2026-07-08
CVE-2025-53829ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attacker with administrative privileges can exploit a path traversal vulnerability in the system to execute arbitrary code. Upgrade ownCloud 10 to version 10.15.3 or later to receive a patch.
high
2026-07-08
CVE-2025-53828SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing application ownCloud Classic. In SharePoint for ownCloud prior to version 0.4.1, which corresponds to ownCloud 10 prior to 10.15.3, an attacker with administrative privileges can use a SSRF vulnerability in the SharePoint app to execute arbitrary code on the system. Upgrade ownCloud 10 to version 10.15.3 or later to receive SharePoint for ownCloud 0.4.1, the fixed version.
high
2026-07-08
CVE-2025-53827ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classic. In versions prior to 10.15.3, the Updater on ownCloud 10 before 10.15.3 has an exposed dangerous method or function. Attackers with administrative privileges may leverage functionality to execute arbitrary code. This issue has been fixed in version 10.15.3.
critical
2026-07-08