NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-46370 Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /ap... 2026-08-26 6.5 NETWORK MEDIUM NVD
CVE-2026-46369 Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses... 2026-08-26 7.5 NETWORK HIGH NVD
CVE-2025-70340 A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionality. An aut... 2026-08-26 N/A None None NVD
CVE-2025-70293 An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation ... 2026-08-26 N/A None None NVD
CVE-2025-70290 An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed o... 2026-08-26 9.8 NETWORK CRITICAL NVD
CVE-2026-79940 Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Control vulnerability. An unauthe... 2026-08-26 5.9 NETWORK MEDIUM NVD
CVE-2026-75466 libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexed-color PNG image with a non-g... 2026-08-26 6.5 NETWORK MEDIUM NVD
CVE-2026-75325 DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' parameters. 2026-08-26 9.8 NETWORK CRITICAL NVD
CVE-2026-71171 Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injec... 2026-08-26 7.2 NETWORK HIGH NVD
CVE-2026-70419 Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injec... 2026-08-26 9.1 NETWORK CRITICAL NVD
CVE-2026-63179 Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, authenticated backend users can ... 2026-08-26 4.9 NETWORK MEDIUM NVD
CVE-2026-51106 An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component 2026-08-26 9.3 NETWORK CRITICAL NVD
CVE-2026-48786 Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/t... 2026-08-26 6.5 NETWORK MEDIUM NVD
CVE-2026-41262 Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET /api/latest/fle... 2026-08-26 4.3 NETWORK MEDIUM NVD
CVE-2026-36851 Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration. 2026-08-26 7.5 NETWORK HIGH NVD