NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-58090 The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. ... 2026-08-26 7.8 LOCAL HIGH NVD
CVE-2026-58089 When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted ... 2026-08-26 7.8 LOCAL HIGH NVD
CVE-2026-57171 Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0... 2026-08-26 7.7 LOCAL HIGH NVD
CVE-2026-57170 Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 thro... 2026-08-26 7.8 LOCAL HIGH NVD
CVE-2026-54467 On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidate... 2026-08-26 7.0 PHYSICAL HIGH NVD
CVE-2026-52776 Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the UR... 2026-08-26 8.6 NETWORK HIGH NVD
CVE-2026-29988 A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware... 2026-08-26 7.6 PHYSICAL HIGH NVD
CVE-2026-80138 ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticate... 2026-08-25 9.8 NETWORK CRITICAL NVD
CVE-2026-70665 Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynam... 2026-08-25 4.2 NETWORK MEDIUM NVD
CVE-2026-55805 Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue... 2026-08-25 5.4 NETWORK MEDIUM NVD
CVE-2026-54757 Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0... 2026-08-25 7.8 LOCAL HIGH NVD
CVE-2026-44476 Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which i... 2026-08-25 6.3 NETWORK MEDIUM NVD
CVE-2026-41707 Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-b... 2026-08-25 7.4 NETWORK HIGH NVD
CVE-2026-18985 Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.... 2026-08-25 8.1 NETWORK HIGH NVD
CVE-2026-18261 Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*. 2026-08-25 5.7 NETWORK MEDIUM NVD