Skip to content

standard

National Vulnerability Database

U.S. government database of standardized vulnerability data, maintained by NIST, which assigns CVSS severity scores and metadata to CVE entries.

Known aliases

  • National Vulnerability Database
  • US NVD

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

Windows DNS Server's 9.8 bug takes one unauthenticated packet to port 53

Microsoft patched CVE-2026-69730, a CVSS 9.8 remote code execution flaw in the Windows DNS Server role reachable with one unauthenticated packet to port 53. In most Active Directory shops that role runs on the domain controller, so the box answering on port 53 also holds the identity database.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+20
Incentives
Insufficient
Confidence40
build1 publisher

vm2's prefix allowlist let one approved module load its unapproved siblings

vm2's maintainer patched a CVSS 9.5 flaw in 3.12.2 where the module allowlist matched an approved path as a bare prefix and cleared a neighboring package. With NodeVM's default host context, the unapproved sibling ran with full Node authority.

Publishers:dev.to

Reality

Evidence62
Adoption
Insufficient
Hype gap+8
Incentives
Insufficient
Confidence58
build1 publisher

Turning off mod_verto retires five of FreeSWITCH's nine June CVEs

Five of nine FreeSWITCH CVEs from June 2026 sit in mod_verto, including an unauthenticated 9.8 heap overflow that unloading the module closes without a patch. The second critical, a 9.1 in the Event Socket Library, stays loaded and reaches any binary linked against libesl.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap0
Incentives30
Confidence55
build1 publisher

Hive's SAML validator hands out a session to any Bearer token you forge

The bypass needs HTTP transport and SAML mode, so it misses the Kerberos default, but Apache published no CVSS vector and NVD has no score, which leaves triage to whoever actually reads hive-site.xml, and the 4.2.1 fix carries two more security bugs with it.

Publishers:dev.to

Reality

Evidence62
Adoption20
Hype gap−8
Incentives42
Confidence58

Earlier coverage

  1. NVD stops scheduling enrichment for roughly 30,000 pre-March-2026 CVEs

    Security · August 28, 2026 · 1 publisher

  2. Kaltura's unpatched player bugs arrive with a coordinator that could not reach the vendor

    Security · August 26, 2026 · 1 publisher

  3. Vulnerability disclosures bent upward in 2026. Algorithm records did not.

    Security · August 25, 2026 · 1 publisher

  4. Calix gateway takes UPnP orders from the internet, and there is no patch to install

    Build · August 24, 2026 · 1 publisher

  5. Firmware CVE intake: the finding is almost never a zero-day, it is a five-year-old BusyBox

    Build · August 22, 2026 · 1 publisher

  6. Fabricated SQLite CVEs cleared NVD, CISA ADP and Red Hat before anyone ran the code

    Build · August 22, 2026 · 1 publisher

  7. Open REST route in WildApricotPress Member Directory hands out members-only emails and phones

    Build · August 22, 2026 · 1 publisher