Total CVEs

149,967

Critical Severity

4,910

High Severity

17,396

Last 7 Days

1,774
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 601 - 620 of 46,372 CVEs

A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected is the function ggml_ftype_to_ggml_type of the file ggml/src/ggml.c. The manipulation of the argument ftype results in reachable assertion. The attack requires a local approach. The project was informed of the problem early through...

Vendor: ggml-org
Product: whisper.cpp
Published: Jul 27, 2026
Source: NVD
CVE-2026-15003 MEDIUM - 5.6

A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file,...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4
Published: Jul 27, 2026
Source: NVD
CVE-2026-59690 HIGH - 8.0

A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be access...

Vendor: Progress Software
Product: LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, Multi Tenant
Published: Jul 27, 2026
Source: NVD
CVE-2026-59689 HIGH - 8.0

An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compro...

Vendor: Progress Software
Product: LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF
Published: Jul 27, 2026
Source: NVD
CVE-2026-59688 HIGH - 8.4

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functio...

Vendor: Progress Software
Product: LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF
Published: Jul 27, 2026
Source: NVD
CVE-2026-59687 HIGH - 8.4

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location managemen...

Vendor: Progress Software
Product: LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF
Published: Jul 27, 2026
Source: NVD
CVE-2026-59686 HIGH - 8.4

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, ...

Vendor: Progress Software
Product: LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF
Published: Jul 27, 2026
Source: NVD

An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users.

Vendor: HCLSoftware
Product: Connections
Published: Jul 27, 2026
Source: NVD

HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data.they are not entitled to, caused by improper handling of request data.

Vendor: HCLSoftware
Product: Connections
Published: Jul 27, 2026
Source: NVD

A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function log_mel_spectrogram of the file src/whisper.cpp. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The pull request to fix this issue awaits acceptance.

Vendor: ggml-org
Product: whisper.cpp
Published: Jul 27, 2026
Source: NVD

The lack of cryptographic mechanisms to ensure the integrity and authenticity of communications in Ghost Robotics' Vision 60 robot (APK v5.5.0) exposes the system to man-in-the-middle attacks. An attacker located on the local network can use ARP spoofing and selective traffic blocking technique...

Vendor: Ghost Robotics
Product: Vision 60
Published: Jul 27, 2026
Source: NVD

An access control vulnerability in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows multiple simultaneous sessions to run without proper client validation or session integrity checks. An attacker with a modified version of the app can connect to the robot during an active,...

Vendor: Ghost Robotics
Product: Vision 60
Published: Jul 27, 2026
Source: NVD

A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robotics' Vision 60 robot allows an unauthenticated attacker connected to the device's internal Wi-Fi network to gain unrestricted access to the web administration interface and the HTTP API. Due to the lack of authorization...

Vendor: Ghost Robotics
Product: Vision 60
Published: Jul 27, 2026
Source: NVD
CVE-2026-66053 MEDIUM - 5.9

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. This replaces CVE-2026-41603

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Jul 27, 2026
Source: NVD
CVE-2026-58662 CRITICAL - 9.1

Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Jul 27, 2026
Source: NVD
CVE-2026-58389 HIGH - 7.5

Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Jul 27, 2026
Source: NVD
CVE-2026-58023 CRITICAL - 9.1

Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Jul 27, 2026
Source: NVD

proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file s...

Vendor: Asseco
Product: proCertum SmartSign
Published: Jul 27, 2026
Source: NVD

proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the document in the appli...

Vendor: Asseco
Product: proCertum SmartSign
Published: Jul 27, 2026
Source: NVD
CVE-2026-55971 CRITICAL - 9.8

Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache Thrift
Published: Jul 27, 2026
Source: NVD