Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42239
Total
3441
Critical
12474
High
12431
Medium
CVE ID Severity Score Description Published
CVE-2026-82860 CRITICAL 9.8 @hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail. Attackers can craft admin-equivalent policy paths that … Aug 31, 2026
CVE-2026-82859 CRITICAL 9.8 hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM boundary restrictions by exploiting … Aug 31, 2026
CVE-2026-82858 CRITICAL 9.8 @hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted. Attackers can supply … Aug 31, 2026
CVE-2026-82857 CRITICAL 9.8 hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without sufficient … Aug 31, 2026
CVE-2026-82856 CRITICAL 9.8 @hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can use ForAnyValue:StringLike operators to hide … Aug 31, 2026
CVE-2026-82855 CRITICAL 9.8 @hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppress violations by submitting unrelated compliant … Aug 31, 2026
CVE-2026-82854 CRITICAL 9.8 Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size … Aug 31, 2026
CVE-2026-82853 MEDIUM 4.9 Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly … Aug 31, 2026
CVE-2026-82668 HIGH 7.3 A security vulnerability has been detected in klaussilveira GitList 2.0.0. Affected by this vulnerability is the function getDefaultBranch of the file src/SCM/System/Git/CommandLine.php of the component … Aug 31, 2026
CVE-2026-82667 MEDIUM 4.7 A vulnerability has been found in yaojingang GEOFlow up to 2.1.0. Impacted is the function DistributionController.isValidHttpEndpoint of the file app/Services/GeoFlow/GenericHttpEndpointResolver.php. Such manipulation of the argument … Aug 31, 2026
CVE-2026-82666 MEDIUM 4.7 A flaw has been found in yaojingang GEOFlow up to 2.1.0. This issue affects the function preview of the file app/Http/Controllers/Admin/SiteThemeEditorController.php of the component Superadmin … Aug 31, 2026
CVE-2026-82665 LOW 3.8 A vulnerability was detected in yaojingang GEOFlow up to 2.1.0. This vulnerability affects the function unlink of the file app/Http/Controllers/Admin/ImageLibraryController.php of the component Image Library … Aug 31, 2026
CVE-2026-82664 MEDIUM 4.3 A security vulnerability has been detected in yaojingang GEOFlow up to 2.1.0. This affects an unknown part of the file app/Http/Controllers/Site/HomeController.php of the component JSON-LD … Aug 31, 2026
CVE-2026-82662 MEDIUM 6.5 Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can … Aug 31, 2026
CVE-2026-82661 MEDIUM 5.4 Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker … Aug 31, 2026
CVE-2026-82660 MEDIUM 5.4 Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying … Aug 31, 2026
CVE-2026-82659 HIGH 7.1 nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request … Aug 31, 2026
CVE-2026-81624 HIGH 7.5 Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain … Aug 31, 2026
CVE-2026-19410 UNKNOWN An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to … Aug 31, 2026
CVE-2024-58379 MEDIUM 5.3 nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers … Aug 31, 2026
CVE-2026-82838 UNKNOWN The default docker image shipped for Venueless did not properly ensure that uploaded SVG files could not be delivered with executable JavaScript content. A valid … Aug 31, 2026
CVE-2026-82631 LOW 2.2 A security flaw has been discovered in valkey-io valkey 9.1.0. The affected element is the function handleClientsBlockedOnKey of the file src/blocked.c of the component Blocked-on-keys … Aug 31, 2026
CVE-2026-82630 HIGH 7.3 A vulnerability was identified in PowerJob up to 5.1.2. Impacted is the function MuConnectionManager.getOrCreateConnection of the file powerjob-server/powerjob-server-starter/src/main/java/tech/powerjob/server/web/controller/TestController.java of the component Transport Endpoint. The manipulation … Aug 31, 2026
CVE-2026-82629 MEDIUM 4.7 A vulnerability was determined in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This issue affects the function MyJwWebJwid3Controller.doUpload of the file jeewx-boot-module-weixin/src/main/java/com/jeecg/p3/open/web/back/MyJwWebJwid3Controller.java of the component doUpload Endpoint. … Aug 31, 2026
CVE-2026-58301 UNKNOWN When Apache Shiro is used with the Jakarta EE integration module, a low-privileged user can craft an HTTP request that causes the server to initiate … Aug 31, 2026