Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51856
Total
4111
Critical
15381
High
15070
Medium
CVE ID Severity Score Description Published
CVE-2026-48022 MEDIUM 6.5 @hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie, and Proxy-Authorization before following a cross-origin redirect, but the … Jul 17, 2026
CVE-2026-44979 UNKNOWN — @hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname, only the Authorization and Cookie headers … Jul 17, 2026
CVE-2026-55518 CRITICAL 9.6 Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in … Jul 17, 2026
CVE-2026-54498 HIGH 8.7 view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base#around_render can return HTML-unsafe strings … Jul 17, 2026
CVE-2026-54497 MEDIUM 6.8 view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base instances retain render-scoped objects … Jul 17, 2026
CVE-2026-54490 UNKNOWN — websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, if this library is used with the permessage-deflate extension, a WebSocket server or … Jul 17, 2026
CVE-2026-54466 UNKNOWN — websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length … Jul 17, 2026
CVE-2026-54244 LOW 3.5 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endpoint for existing entries and terms … Jul 17, 2026
CVE-2026-54243 MEDIUM 6.1 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, form submission values in src/Forms/Exporters/CsvExporter.php were not neutralized for … Jul 17, 2026
CVE-2026-54242 MEDIUM 4.9 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, the Glide image proxy's URL validation in src/Imaging/RemoteUrlValidator.php and … Jul 17, 2026
CVE-2026-54163 MEDIUM 4.7 secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds the Content-Security-Policy value by stitching directives with ; separators, and … Jul 17, 2026
CVE-2026-54159 CRITICAL 10.0 PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected search filters from the request URL, … Jul 17, 2026
CVE-2026-53727 UNKNOWN — css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#read_remote_file in lib/css_parser/parser.rb, and therefore load_uri! and the @import-following branch of add_block!, issued HTTP and … Jul 17, 2026
CVE-2026-52584 UNKNOWN — Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive information via the DecodeImageAPNG function Jul 17, 2026
CVE-2026-52348 UNKNOWN — cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java. Jul 17, 2026
CVE-2026-52203 UNKNOWN — An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter. Jul 17, 2026
CVE-2026-50274 HIGH 7.5 Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monitoring. Prior to 2.8.1, Datadog tracing libraries that implement W3C … Jul 17, 2026
CVE-2026-50272 HIGH 7.5 dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in packages/dd-trace/src/baggage.js and packages/dd-trace/src/opentracing/propagation/text_map.js parsed incoming baggage HTTP headers without enforcing … Jul 17, 2026
CVE-2026-50271 HIGH 7.5 Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without … Jul 17, 2026
CVE-2026-49977 MEDIUM 4.3 tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.33.0, tarteaucitron.cookie.purge() is called on any element with the purgeBtn class and does not check … Jul 17, 2026
CVE-2026-48062 CRITICAL 9.8 CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived guessed extension instead of the … Jul 17, 2026
CVE-2026-45785 MEDIUM 6.2 OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Storage. In 3.1.3 and earlier, … Jul 17, 2026
CVE-2026-45784 UNKNOWN — rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding … Jul 17, 2026
CVE-2026-44891 HIGH 7.5 Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.stomp.StompSubframeDecoder fails to limit the total number … Jul 17, 2026
CVE-2026-16074 MEDIUM 6.3 A vulnerability was detected in AstrBotDevs AstrBot up to 4.25.2. This affects the function update_plugin/update_all_plugins of the file astrbot/dashboard/routes/plugin.py of the component Plugin Update Handler. … Jul 17, 2026