NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-70634 TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compre... 2026-08-06 8.1 NETWORK HIGH NVD
CVE-2026-70633 TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compression reverse row iterator that... 2026-08-06 6.5 NETWORK MEDIUM NVD
CVE-2026-70632 FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decode... 2026-08-06 7.8 LOCAL HIGH NVD
CVE-2026-70631 FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in lib... 2026-08-06 5.5 LOCAL MEDIUM NVD
CVE-2026-70630 FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (lib... 2026-08-06 5.5 LOCAL MEDIUM NVD
CVE-2026-70629 FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/... 2026-08-06 5.5 LOCAL MEDIUM NVD
CVE-2026-70628 FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub... 2026-08-06 7.8 LOCAL HIGH NVD
CVE-2026-70559 Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-l... 2026-08-06 7.5 NETWORK HIGH NVD
CVE-2026-70558 Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with... 2026-08-06 9.8 NETWORK CRITICAL NVD
CVE-2026-70557 diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of any entity and returns those v... 2026-08-06 6.5 NETWORK MEDIUM NVD
CVE-2026-68480 In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt injection An attacker injecting... 2026-08-06 N/A None None NVD
CVE-2026-67689 SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated l... 2026-08-06 9.8 NETWORK CRITICAL NVD
CVE-2026-67688 ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker... 2026-08-06 9.8 NETWORK CRITICAL NVD
CVE-2026-67687 Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleControl... 2026-08-06 8.8 NETWORK HIGH NVD
CVE-2026-67622 Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attack... 2026-08-06 9.9 NETWORK CRITICAL NVD