NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-15387 GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under cer... 2026-08-26 4.3 NETWORK MEDIUM NVD
CVE-2026-12717 An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service versions prior to 2026-05-0... 2026-08-26 9.4 NETWORK CRITICAL NVD
CVE-2025-10903 GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under ce... 2026-08-26 6.5 NETWORK MEDIUM NVD
CVE-2026-79619 On Linux, several OpenZFS ioctl authorization checks accept a capability held only within a user-created, unprivileged namespace as equivalent to real... 2026-08-26 7.3 LOCAL HIGH NVD
CVE-2026-77658 A stack-based buffer overflow vulnerability exists in the Dia diagram editor when processing Network Bus objects from Dia XML project files. In objec... 2026-08-26 7.8 LOCAL HIGH NVD
CVE-2026-63041 Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attacker to escalate privilege or pe... 2026-08-26 8.8 NETWORK HIGH NVD
CVE-2026-80206 NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep_node_action function compiles... 2026-08-26 5.9 NETWORK MEDIUM NVD
CVE-2026-80205 NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSearcher.findall() methods that ac... 2026-08-26 7.5 NETWORK HIGH NVD
CVE-2026-80204 The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 does not apply the API-key scope cap in the injectSecurityTab() function of BlueprintContr... 2026-08-26 5.4 NETWORK MEDIUM NVD
CVE-2026-80203 The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across ... 2026-08-26 9.8 NETWORK CRITICAL NVD
CVE-2026-80350 OneUptime's webhook target check rejects private and loopback addresses given in IPv4 form and a small set of IPv6 forms, but has no case for the IPv4... 2026-08-26 7.1 NETWORK HIGH NVD
CVE-2026-80349 TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header. app.js sets Koa's proxy option to true without n... 2026-08-26 9.8 NETWORK CRITICAL NVD
CVE-2026-80348 TarsWeb enforces its per-application roles by calling AuthService from individual controller methods, and four methods in app/controller/patch/PatchCo... 2026-08-26 8.8 NETWORK HIGH NVD
CVE-2026-80347 mcp-fetch checks a fetch target against its SSRF guard without removing the brackets that surround an IPv6 literal. isSafeUrl reads the hostname from ... 2026-08-26 7.5 NETWORK HIGH NVD
CVE-2026-80346 StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. Every other statement type routed through AuthorizerStmt... 2026-08-26 7.1 NETWORK HIGH NVD