NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-71054 Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily exploitable vulnerability all... 2026-08-26 6.5 NETWORK MEDIUM NVD
CVE-2026-68863 Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote acces... 2026-08-26 7.5 NETWORK HIGH NVD
CVE-2026-68861 Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injectio... 2026-08-26 8.8 NETWORK HIGH NVD
CVE-2026-68000 The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directly concatenated into the LIMIT ... 2026-08-26 N/A None None NVD
CVE-2026-67275 Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerability. An unauthenticated attac... 2026-08-26 5.3 NETWORK MEDIUM NVD
CVE-2026-66003 Frappe is a full-stack web application framework written in Python and JavaScript. Prior to version 15.115.0, an access control bypass in the REST API... 2026-08-26 7.1 NETWORK HIGH NVD
CVE-2026-60004 Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. 2026-08-26 9.8 NETWORK CRITICAL NVD
CVE-2026-54245 Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional access integration in Fleet Pre... 2026-08-26 7.6 NETWORK HIGH NVD
CVE-2026-49809 Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti... 2026-08-26 6.5 NETWORK MEDIUM NVD
CVE-2026-47848 In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client may leak credentials. In order... 2026-08-26 6.1 NETWORK MEDIUM NVD
CVE-2026-47844 In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for this to happen, the server mus... 2026-08-26 5.3 NETWORK MEDIUM NVD
CVE-2026-47843 In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrectly reuse a previously configur... 2026-08-26 3.7 NETWORK LOW NVD
CVE-2026-47842 Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as the encryption mode encrypt data... 2026-08-26 6.5 NETWORK MEDIUM NVD
CVE-2026-47834 Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from untrusted sources. Spring Data JPA 4.1.... 2026-08-26 4.8 NETWORK MEDIUM NVD
CVE-2026-46371 Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (... 2026-08-26 6.5 NETWORK MEDIUM NVD