U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

NVD Dashboard

CVEs Received and Processed

CVEs Received and Processed

Please Wait

CVE Status Count

Please Wait

CVSS Score Spread

Please Wait

CVSS V3 Score Distribution

Severity Number of Vulns

CVSS V2 Score Distribution

Severity Number of Vulns


For information on how to the cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-54345 - gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from an attacker-controlled AVP Length field, so a vendor-flagged AVP wh... read CVE-2026-54345
    Published: July 28, 2026; 1:16:51 PM -0400

    V3.1: 7.5 HIGH

  • CVE-2026-63248 - In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable diagnostics over a None/None endpoint without a certificate; with a trusted client application certif... read CVE-2026-63248
    Published: August 04, 2026; 9:18:55 AM -0400

    V3.1: 6.5 MEDIUM

  • CVE-2026-63252 - In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote unauthenticated client to exhaust pooled direct memory by repeatedly sending... read CVE-2026-63252
    Published: August 04, 2026; 9:18:55 AM -0400

    V3.1: 7.5 HIGH

  • CVE-2026-59878 - Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value... read CVE-2026-59878
    Published: July 28, 2026; 10:16:38 AM -0400

  • CVE-2026-61487 - Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL by sending to an ActiveMQ temporary composite destination whose phys... read CVE-2026-61487
    Published: July 28, 2026; 10:16:38 AM -0400

  • CVE-2026-66299 - Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the s... read CVE-2026-66299
    Published: July 28, 2026; 11:17:50 AM -0400

  • CVE-2026-66713 - Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat  (only when Tribes clustering is enabled, which is off by default) allows an ... read CVE-2026-66713
    Published: July 28, 2026; 11:17:50 AM -0400

  • CVE-2021-41864 - prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.
    Published: October 01, 2021; 8:15:07 PM -0400

    V3.1: 7.8 HIGH
    V2.0: 4.6 MEDIUM

  • CVE-2026-66390 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to ver... read CVE-2026-66390
    Published: July 27, 2026; 1:16:41 PM -0400

  • CVE-2021-45485 - In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among... read CVE-2021-45485
    Published: December 24, 2021; 9:15:06 PM -0500

    V3.1: 7.5 HIGH
    V2.0: 5.0 MEDIUM

  • CVE-2026-66391 - Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which... read CVE-2026-66391
    Published: July 27, 2026; 1:16:41 PM -0400

  • CVE-2026-65946 - Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0
    Published: July 29, 2026; 9:19:11 AM -0400

  • CVE-2026-65944 - Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0
    Published: July 29, 2026; 9:19:11 AM -0400

  • CVE-2026-65943 - Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0
    Published: July 29, 2026; 9:19:11 AM -0400

  • CVE-2026-65885 - Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the require... read CVE-2026-65885
    Published: July 29, 2026; 9:19:10 AM -0400

    V3.1: 8.8 HIGH

  • CVE-2026-65884 - Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.
    Published: July 29, 2026; 9:19:10 AM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2026-65883 - Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.
    Published: July 29, 2026; 7:16:50 AM -0400

    V3.1: 9.8 CRITICAL

  • CVE-2026-59243 - The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an... read CVE-2026-59243
    Published: July 29, 2026; 6:16:44 AM -0400

  • CVE-2026-50622 - Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoints allows any authenticated user, regardless of their assigned role, to perform administrative operations. Affect Version:... read CVE-2026-50622
    Published: July 29, 2026; 6:16:41 AM -0400

  • CVE-2026-23904 - Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts,... read CVE-2026-23904
    Published: July 29, 2026; 6:16:40 AM -0400