U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-20058 - Multiple Cisco products are affected by vulnerabilities in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. These vulnerabilities are due to improper error checking whe... read CVE-2026-20058
    Published: March 04, 2026; 1:16:20 PM -0500

  • CVE-2025-10592 - A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. This impacts an unknown function of the file mysearch.php of the component POST Parameter Handler. Such manipulation of the argument search_field/sea... read CVE-2025-10592
    Published: September 17, 2025; 9:15:33 AM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-20065 - Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. Th... read CVE-2026-20065
    Published: March 04, 2026; 1:16:21 PM -0500

  • CVE-2026-20066 - Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. Th... read CVE-2026-20066
    Published: March 04, 2026; 1:16:21 PM -0500

  • CVE-2026-6695 - A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA... read CVE-2026-6695
    Published: August 03, 2026; 2:16:41 AM -0400

    V3.1: 5.5 MEDIUM

  • CVE-2026-20067 - Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. ... read CVE-2026-20067
    Published: March 04, 2026; 1:16:21 PM -0500

  • CVE-2026-4793 - An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.
    Published: August 03, 2026; 3:16:43 AM -0400

    V3.1: 7.8 HIGH

  • CVE-2026-14587 - Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends a selected protocol version followed by 32 continuation bytes in the capability mask, th... read CVE-2026-14587
    Published: August 05, 2026; 1:16:41 PM -0400

    V3.1: 7.5 HIGH

  • CVE-2026-20348 - A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability ... read CVE-2026-20348
    Published: August 07, 2026; 1:17:03 PM -0400

  • CVE-2026-59087 - A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This cou... read CVE-2026-59087
    Published: August 10, 2026; 7:17:26 AM -0400

    V3.1: 7.8 HIGH

  • CVE-2026-59088 - A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI image files. This occurs due to an incorrect calculation during memory allocation for image buffers, where the multiplication of ... read CVE-2026-59088
    Published: August 10, 2026; 8:17:19 AM -0400

    V3.1: 5.5 MEDIUM

  • CVE-2026-59090 - A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an ... read CVE-2026-59090
    Published: August 10, 2026; 9:19:51 AM -0400

    V3.1: 9.9 CRITICAL

  • CVE-2026-59091 - A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking a user into opening a specially crafted image file. This could lead to unexpected application ... read CVE-2026-59091
    Published: August 10, 2026; 3:17:30 PM -0400

    V3.1: 7.8 HIGH

  • CVE-2026-48617 - A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerabili... read CVE-2026-48617
    Published: June 18, 2026; 1:16:31 PM -0400

    V3.1: 8.2 HIGH

  • CVE-2026-55877 - Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() Twig function is marked is_safe=['html'] and Icon::toHtml() inlines SVG source verbatim, allowing unsanitized local SVG files or... read CVE-2026-55877
    Published: July 08, 2026; 6:17:15 PM -0400

  • CVE-2026-12228 - A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint stores attacker-controlled `prompt_content` into `DBDirectMessage.content` without server-side san... read CVE-2026-12228
    Published: July 18, 2026; 5:17:03 PM -0400

    V3.1: 5.4 MEDIUM

  • CVE-2026-2445 - The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads. An atta... read CVE-2026-2445
    Published: July 20, 2026; 4:16:30 AM -0400

  • CVE-2026-33327 - libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overf... read CVE-2026-33327
    Published: July 20, 2026; 1:17:06 PM -0400

    V3.1: 7.8 HIGH

  • CVE-2021-26858 - Microsoft Exchange Server Remote Code Execution Vulnerability
    Published: March 02, 2021; 7:15:12 PM -0500

    V2.0: 6.8 MEDIUM

  • CVE-2026-64849 - MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/va... read CVE-2026-64849
    Published: August 17, 2026; 6:17:23 PM -0400

Created September 20, 2022 , Updated August 27, 2024