NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-58096 LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options... 2026-08-26 8.8 NETWORK HIGH NVD
CVE-2026-58095 mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to o... 2026-08-26 8.8 NETWORK HIGH NVD
CVE-2026-58094 The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory object. This is intended to be used immediately after cre... 2026-08-26 7.8 LOCAL HIGH NVD
CVE-2026-58093 The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not revalid... 2026-08-26 7.0 LOCAL HIGH NVD
CVE-2026-15203 Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read... 2026-08-26 9.3 NETWORK CRITICAL NVD
CVE-2026-9805 SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size and could cause buffer overfl... 2026-08-26 2.7 PHYSICAL LOW NVD
CVE-2026-80214 LibreNMS’s Virtualization Discovery module is vulnerable to command line injection. An authenticated admin user can execute arbitrary code on the host... 2026-08-26 8.6 NETWORK HIGH NVD
CVE-2026-80202 Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or othe... 2026-08-26 8.8 NETWORK HIGH NVD
CVE-2026-80201 Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiT... 2026-08-26 2.0 NETWORK LOW NVD
CVE-2026-80200 Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parame... 2026-08-26 4.7 NETWORK MEDIUM NVD
CVE-2026-80199 Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames vi... 2026-08-26 3.7 NETWORK LOW NVD
CVE-2026-80198 Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access ... 2026-08-26 7.5 NETWORK HIGH NVD
CVE-2026-80197 Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints that allows authenticated user... 2026-08-26 4.3 NETWORK MEDIUM NVD
CVE-2026-80196 Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes because the LoginLi... 2026-08-26 7.5 NETWORK HIGH NVD
CVE-2026-80195 Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /api/teams/{id}), which re... 2026-08-26 5.4 NETWORK MEDIUM NVD