Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51713
Total
4098
Critical
15342
High
14990
Medium
CVE ID Severity Score Description Published
CVE-2026-64616 UNKNOWN — Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ndarray.h … Jul 21, 2026
CVE-2026-64615 UNKNOWN — Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in graph.h … Jul 21, 2026
CVE-2026-64614 UNKNOWN — Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in deque.h … Jul 21, 2026
CVE-2026-64613 UNKNOWN — Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOW. The segment is created in buf_generic.h with open(path, … Jul 21, 2026
CVE-2026-59147 UNKNOWN — Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find. The attach-time validator dsu_validate_header checks the header … Jul 21, 2026
CVE-2026-59146 UNKNOWN — Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph_walk_cell and sph_alloc_slot. The attach-time validator … Jul 21, 2026
CVE-2026-59145 UNKNOWN — Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find. The attach-time validator si_validate_header is thorough … Jul 21, 2026
CVE-2026-59144 UNKNOWN — Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time validator ring_validate_header checks the capacity-overflow and … Jul 21, 2026
CVE-2026-59143 UNKNOWN — Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_contains_locked. The attach-time validator rb_validate_header checks the … Jul 21, 2026
CVE-2026-56852 UNKNOWN — A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. Jul 21, 2026
CVE-2026-56146 MEDIUM 5.4 Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with … Jul 21, 2026
CVE-2026-56145 MEDIUM 6.5 Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL … Jul 21, 2026
CVE-2026-56144 MEDIUM 5.3 Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By … Jul 21, 2026
CVE-2026-50759 UNKNOWN — An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instance/{instance_id} endpoints with no authentication. Jul 21, 2026
CVE-2026-50758 UNKNOWN — Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter Jul 21, 2026
CVE-2026-50757 UNKNOWN — Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server Jul 21, 2026
CVE-2026-50756 UNKNOWN — An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component Jul 21, 2026
CVE-2026-50755 UNKNOWN — An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value Jul 21, 2026
CVE-2026-49092 MEDIUM 4.3 Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under … Jul 21, 2026
CVE-2026-47671 MEDIUM 5.4 Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost configserver` used by `nhost dev` … Jul 21, 2026
CVE-2026-47667 HIGH 7.5 CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field is read as an `unsigned int` from … Jul 21, 2026
CVE-2026-46600 UNKNOWN — Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. Jul 21, 2026
CVE-2026-46403 MEDIUM 6.3 Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithTypedArguments` as a read-only execution mechanism. The hook saves the … Jul 21, 2026
CVE-2026-42397 MEDIUM 6.5 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can … Jul 21, 2026
CVE-2026-30632 UNKNOWN — Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool. Jul 21, 2026