NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-81028 ZLMediaKit confines the downloadFile API to a configured set of root directories with a prefix comparison that does not account for directory boundari... 2026-08-26 4.9 NETWORK MEDIUM NVD
CVE-2026-81027 one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a specific channel either through a... 2026-08-26 8.5 NETWORK HIGH NVD
CVE-2026-80428 ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIAS/AuthShibboleth/resource... 2026-08-26 9.8 NETWORK CRITICAL NVD
CVE-2026-80427 bestzip builds the argument list for the system zip utility without separating options from operands. The destination archive path and the caller-supp... 2026-08-26 8.4 LOCAL HIGH NVD
CVE-2026-80426 FiftyOne renders a dataset field's description as markup. The sidebar field-information component at app/packages/core/src/components/FieldLabelAndInf... 2026-08-26 7.1 NETWORK HIGH NVD
CVE-2026-54614 DebugKit provides a debugging toolbar for CakePHP applications. Prior to 4.10.3 and 5.2.4, the DebugKit MailPreview feature in src/Controller/MailPrev... 2026-08-26 4.3 NETWORK MEDIUM NVD
CVE-2026-54606 SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 3.1.4, the SunEditor Embed plugin in src/p... 2026-08-26 8.5 NETWORK HIGH NVD
CVE-2026-54569 SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits un... 2026-08-26 9.8 NETWORK CRITICAL NVD
CVE-2026-48549 Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi. When no Cookie header is present, the double-submit ... 2026-08-26 6.5 NETWORK MEDIUM NVD
CVE-2026-48548 Nagios Core before 4.5.12 contains a cross-site request forgery vulnerability in cmd.cgi where the CSRF protection mechanism passes validation when th... 2026-08-26 6.5 NETWORK MEDIUM NVD
CVE-2026-80589 In the Linux kernel, the following vulnerability has been resolved: block: stop the timeout timer when releasing a never added disk disk_release() u... 2026-08-26 9.8 NETWORK CRITICAL NVD
CVE-2026-80588 In the Linux kernel, the following vulnerability has been resolved: mptcp: reclaim forward-allocated memory on RX path errors After commit 9db5b3cec... 2026-08-26 7.5 NETWORK HIGH NVD
CVE-2026-80587 In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboptions Some MPTCP suboptions are mutual... 2026-08-26 9.8 NETWORK CRITICAL NVD
CVE-2026-80586 In the Linux kernel, the following vulnerability has been resolved: mptcp: options: reset DSS fields in case of unexpected size A remote peer could ... 2026-08-26 9.8 NETWORK CRITICAL NVD
CVE-2026-80585 In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with SYN data Passive TCP Fast Open ac... 2026-08-26 9.4 NETWORK CRITICAL NVD