U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-66273 - A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35... read CVE-2026-66273
    Published: August 05, 2026; 2:16:38 AM -0400

  • CVE-2026-66257 - A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, w... read CVE-2026-66257
    Published: August 05, 2026; 2:16:38 AM -0400

  • CVE-2026-34486 - Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to... read CVE-2026-34486
    Published: April 09, 2026; 4:16:25 PM -0400

  • CVE-2026-66310 - External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
    Published: August 03, 2026; 8:17:38 PM -0400

    V3.1: 7.1 HIGH

  • CVE-2026-62515 - Vulnerability in the Oracle Advanced Planning Command Center product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged att... read CVE-2026-62515
    Published: July 21, 2026; 6:19:06 PM -0400

    V3.1: 7.6 HIGH

  • CVE-2026-62514 - Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low priv... read CVE-2026-62514
    Published: July 21, 2026; 6:19:06 PM -0400

  • CVE-2026-65802 - External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
    Published: August 03, 2026; 8:17:37 PM -0400

  • CVE-2026-62516 - Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with net... read CVE-2026-62516
    Published: July 21, 2026; 6:19:06 PM -0400

  • CVE-2026-61041 - Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Product Security). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with net... read CVE-2026-61041
    Published: July 21, 2026; 6:18:35 PM -0400

  • CVE-2026-62493 - Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.11-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network a... read CVE-2026-62493
    Published: July 21, 2026; 6:19:05 PM -0400

  • CVE-2026-62513 - Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low priv... read CVE-2026-62513
    Published: July 21, 2026; 6:19:06 PM -0400

  • CVE-2026-62518 - Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with n... read CVE-2026-62518
    Published: July 21, 2026; 6:19:07 PM -0400

    V3.1: 7.6 HIGH

  • CVE-2026-62517 - Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker wit... read CVE-2026-62517
    Published: July 21, 2026; 6:19:06 PM -0400

  • CVE-2026-43910 - Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2.1 until 10.1.1, when directConnect(true) is enabled, AppiumCommandExecutor.setDirectConnect() reads the directConnectHost... read CVE-2026-43910
    Published: July 28, 2026; 12:18:12 PM -0400

  • CVE-2026-66032 - libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a serv... read CVE-2026-66032
    Published: July 24, 2026; 1:17:35 PM -0400

  • CVE-2026-66036 - FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when... read CVE-2026-66036
    Published: July 24, 2026; 4:18:20 PM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-66037 - FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying... read CVE-2026-66037
    Published: July 24, 2026; 4:18:20 PM -0400

    V3.1: 5.5 MEDIUM

  • CVE-2026-66038 - FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes t... read CVE-2026-66038
    Published: July 24, 2026; 4:18:20 PM -0400

    V3.1: 6.5 MEDIUM

  • CVE-2026-66039 - FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attack... read CVE-2026-66039
    Published: July 24, 2026; 4:18:20 PM -0400

    V3.1: 7.8 HIGH

  • CVE-2026-66040 - FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. ... read CVE-2026-66040
    Published: July 24, 2026; 4:18:21 PM -0400

    V3.1: 8.8 HIGH

Created September 20, 2022 , Updated August 27, 2024