NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-65637 Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 t... 2026-08-25 9.8 NETWORK CRITICAL NVD
CVE-2026-65183 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user t... 2026-08-25 8.1 NETWORK HIGH NVD
CVE-2026-65182 Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path ... 2026-08-25 9.1 NETWORK CRITICAL NVD
CVE-2026-63404 Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnerable to an insecure tempor... 2026-08-25 7.3 LOCAL HIGH NVD
CVE-2026-63403 Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the server is vulnerable to an unauthenticated denial of service in... 2026-08-25 8.7 NETWORK HIGH NVD
CVE-2026-62865 Typebot is an open-source chatbot builder. In self-hosted versions prior to 3.18.0, the server-side Send Email integration block allows arbitrary read... 2026-08-25 8.7 NETWORK HIGH NVD
CVE-2026-62862 Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1, the default passwordless email magic-link authenticatio... 2026-08-25 9.1 NETWORK CRITICAL NVD
CVE-2026-62861 TypeBot is a chatbot builder tool. Prior to 3.18.0, any authenticated non-guest workspace member can remove another workspace's public custom domain a... 2026-08-25 6.4 NETWORK MEDIUM NVD
CVE-2026-32637 Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. Prior to 1.18.1, an attack... 2026-08-25 5.9 NETWORK MEDIUM NVD
CVE-2026-80104 DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in ... 2026-08-25 9.8 NETWORK CRITICAL NVD
CVE-2026-80101 A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image file, the plugin validates the image width and bytes-pe... 2026-08-25 4.4 LOCAL MEDIUM NVD
CVE-2026-79293 Information leak in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML pag... 2026-08-25 6.5 NETWORK MEDIUM NVD
CVE-2026-79292 Integer overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potential... 2026-08-25 8.3 NETWORK HIGH NVD
CVE-2026-79291 Information leak in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Ch... 2026-08-25 6.5 NETWORK MEDIUM NVD
CVE-2026-79290 Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted H... 2026-08-25 9.6 NETWORK CRITICAL NVD