Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51713
Total
4098
Critical
15342
High
14990
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-24232 | MEDIUM | 4.3 | NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code … | Jul 21, 2026 |
| CVE-2026-16454 | MEDIUM | 4.3 | In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identified in the Direct Device Integration (DDI) Controller. This … | Jul 21, 2026 |
| CVE-2026-16451 | MEDIUM | 6.3 | A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the file /api/system/file/upload of the component com.zs.file.controller.SysFileController. … | Jul 21, 2026 |
| CVE-2026-15829 | UNKNOWN | — | A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters … | Jul 21, 2026 |
| CVE-2026-15793 | UNKNOWN | — | BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this … | Jul 21, 2026 |
| CVE-2026-15792 | UNKNOWN | — | A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. | Jul 21, 2026 |
| CVE-2026-15791 | UNKNOWN | — | A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally … | Jul 21, 2026 |
| CVE-2026-15789 | UNKNOWN | — | A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs … | Jul 21, 2026 |
| CVE-2026-15724 | HIGH | 8.7 | In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary … | Jul 21, 2026 |
| CVE-2026-15432 | UNKNOWN | — | When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows an attacker to use … | Jul 21, 2026 |
| CVE-2026-15342 | UNKNOWN | — | Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to … | Jul 21, 2026 |
| CVE-2025-68640 | MEDIUM | 5.3 | The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove … | Jul 21, 2026 |
| CVE-2026-64825 | CRITICAL | 9.3 | Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem … | Jul 21, 2026 |
| CVE-2026-64824 | HIGH | 8.4 | Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths … | Jul 21, 2026 |
| CVE-2026-64823 | MEDIUM | 4.7 | Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_media_image() method that allows attackers controlling a Shelly device's thumb field … | Jul 21, 2026 |
| CVE-2026-56586 | LOW | 3.1 | HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data. | Jul 21, 2026 |
| CVE-2026-56585 | LOW | 3.1 | HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce … | Jul 21, 2026 |
| CVE-2026-47396 | CRITICAL | 9.8 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent control API without authentication when `CALL_SERVER_TOKEN` is not … | Jul 21, 2026 |
| CVE-2026-47395 | MEDIUM | 5.5 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, PraisonAI's direct-prompt CLI automatically expands `@url:` mentions … | Jul 21, 2026 |
| CVE-2026-47394 | UNKNOWN | — | PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is incomplete. The original advisory description named four vulnerable … | Jul 21, 2026 |
| CVE-2026-47393 | CRITICAL | 9.8 | PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.generate_api_server_code`) that emits a Flask API server with authentication disabled by … | Jul 21, 2026 |
| CVE-2026-47392 | CRITICAL | 9.9 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tools/python_tools.py` (v1.6.37, subprocess sandbox mode) … | Jul 21, 2026 |
| CVE-2026-47391 | CRITICAL | 9.8 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC endpoint and registers a `calculate(expression)` … | Jul 21, 2026 |
| CVE-2026-47390 | MEDIUM | 5.5 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `spider_tools` URL validation can be bypassed using … | Jul 21, 2026 |
| CVE-2026-28321 | CRITICAL | 9.1 | SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate … | Jul 21, 2026 |