CVE watch

Every disclosure pulled from the NVD feed, filterable by severity.

All Critical High Medium Low Unknown
CVE-2026-12554 UNKNOWN

CVE-2026-12554 published: Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.

View full advisory →
CVE-2026-9728 MEDIUM

CVE-2026-9728 published: The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out of live userspace memory, and then forwarded the original, still-mutable userspace struct mbox_msg...

View full advisory →
CVE-2026-78387 UNKNOWN

CVE-2026-78387 published: RansomLook contains an authorization weakness in the web-based configuration editor exposed through the /admin/config endpoint. The endpoint requires an authenticated session but does not perform an explicit privilege or administrator authorization check be...

View full advisory →
CVE-2026-78391 UNKNOWN

CVE-2026-78391 published: RansomLook contains a stored cross-site scripting (XSS) vulnerability in the cryptocurrency wallet detail view. Cryptocurrency addresses and blockchain names originating from external sources, including the public crowd-sourced ransomwhe.re feed, were store...

View full advisory →
CVE-2026-78414 HIGH

CVE-2026-78414 published: Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux, Windows and MacOS allows an adjacent-network attacker to execute arbitrary JavaScript in the browser of an authenticated administrator an...

View full advisory →
CVE-2026-76054 UNKNOWN

CVE-2026-76054 published: Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute code within the scanned project's build to obtain the Black Duck API token via the ambient process environment, whic...

View full advisory →
CVE-2026-76055 UNKNOWN

CVE-2026-76055 published: Improper Neutralization of Special Elements used in an OS Command in the package manager component of Black Duck blackduck-c-cpp before 3.0.7 allows an actor able to create a file within the scanned build directory to execute operating system commands as th...

View full advisory →
CVE-2026-65053 MEDIUM

CVE-2026-65053 published: Horde IMP's AppleDouble MIME viewer writes an attacker-controlled attachment name into an HTML status block without escaping it. In lib/Mime/Viewer/Appledouble.php, _IMPrender() obtains the name of the data part with IMP_Contents::getPartName(), which retur...

View full advisory →
CVE-2026-39915 HIGH

CVE-2026-39915 published: TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to inject arbitrary HTTP headers and response body content by embedding unsanitized carriage return and line feed sequences in the rt URL parameter, which is reflect...

View full advisory →
CVE-2026-19874 CRITICAL

CVE-2026-19874 published: A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The affected function processes a list of kicked player identifiers using the lobby data ...

View full advisory →
CVE-2026-21755 MEDIUM

CVE-2026-21755 published: HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or credential stuffing attacks, or cause a denial of service.

View full advisory →
CVE-2026-39914 MEDIUM

CVE-2026-39914 published: TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arbitrary SQL queries to a privileged dashboard Excel export endpoint intended for administrative use only. Attackers can craft and submit u...

View full advisory →
CVE-2026-76843 HIGH

CVE-2026-76843 published: The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a model file. Loading a mode...

View full advisory →
CVE-2026-76844 HIGH

CVE-2026-76844 published: webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against a traversal guard and then slicing it at a fixed character offset. The guard, UP_PATH_REGEXP applied to path.normalize(`./${pathname}`), ...

View full advisory →
CVE-2026-76840 CRITICAL

CVE-2026-76840 published: RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as explorer.exe calls IStream::Read with a buffer of cb bytes, CliprdrStream_Read in libs/cl...

View full advisory →
CVE-2026-76841 HIGH

CVE-2026-76841 published: Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. Six loader call sites pass trust_remote_code=True as a literal or as an unconditional default: RerankModel._...

View full advisory →
CVE-2026-76842 HIGH

CVE-2026-76842 published: The Mercado Pago Node.js SDK interpolates caller-supplied identifiers into API request paths without percent-encoding them, so characters that are structural in a URL survive into the outgoing request. The payment (get, capture, cancel), paymentRefund (crea...

View full advisory →
CVE-2026-67602 CRITICAL

CVE-2026-67602 published: phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure object cache keying mechanism. The cache is keyed by lookup value alone without incl...

View full advisory →
CVE-2026-59567 HIGH

CVE-2026-59567 published: Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context.

View full advisory →
CVE-2026-59568 CRITICAL

CVE-2026-59568 published: Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.

View full advisory →