Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51943
Total
4127
Critical
15407
High
15098
Medium
CVE ID Severity Score Description Published
CVE-2026-16081 MEDIUM 4.3 A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file web/backend/api/auth.go. Executing a manipulation can … Jul 18, 2026
CVE-2026-16077 MEDIUM 5.3 A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5. Impacted is the function _normalize_rw_path of the file astrbot/core/tools/computer_tools/fs.py of the component Filesystem Computer-Use Tool. … Jul 18, 2026
CVE-2026-16076 MEDIUM 6.3 A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_send of the file astrbot/dashboard/routes/open_api.py of the component API. … Jul 18, 2026
CVE-2026-9734 MEDIUM 4.3 The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is … Jul 18, 2026
CVE-2026-16075 MEDIUM 4.3 A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. This vulnerability affects the function OpenApiRoute.get_chat_sessions of the file astrbot/dashboard/routes/open_api.py of the component session-listing … Jul 18, 2026
CVE-2026-57980 MEDIUM 5.4 Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. Jul 17, 2026
CVE-2026-56741 HIGH 7.5 JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an … Jul 17, 2026
CVE-2026-56740 HIGH 7.5 JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not limit the … Jul 17, 2026
CVE-2026-56171 HIGH 7.1 Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network. Jul 17, 2026
CVE-2026-54335 LOW 3.7 Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In 5.0.44 and earlier, the _.merge(target, source) utility exported by … Jul 17, 2026
CVE-2026-49485 HIGH 7.5 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.9 and 6.9.4.2, all implementations of FHIRPathEngine … Jul 17, 2026
CVE-2026-48049 MEDIUM 5.3 @hapi/inert provides static file and directory handlers for hapi.js. From 4.0.0 to 7.1.0, @hapi/inert serves static files from a directory configured with path in the … Jul 17, 2026
CVE-2026-48022 MEDIUM 6.5 @hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie, and Proxy-Authorization before following a cross-origin redirect, but the … Jul 17, 2026
CVE-2026-44979 UNKNOWN — @hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname, only the Authorization and Cookie headers … Jul 17, 2026
CVE-2026-55518 CRITICAL 9.6 Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in … Jul 17, 2026
CVE-2026-54498 HIGH 8.7 view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base#around_render can return HTML-unsafe strings … Jul 17, 2026
CVE-2026-54497 MEDIUM 6.8 view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base instances retain render-scoped objects … Jul 17, 2026
CVE-2026-54490 UNKNOWN — websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, if this library is used with the permessage-deflate extension, a WebSocket server or … Jul 17, 2026
CVE-2026-54466 UNKNOWN — websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length … Jul 17, 2026
CVE-2026-54244 LOW 3.5 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endpoint for existing entries and terms … Jul 17, 2026
CVE-2026-54243 MEDIUM 6.1 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, form submission values in src/Forms/Exporters/CsvExporter.php were not neutralized for … Jul 17, 2026
CVE-2026-54242 MEDIUM 4.9 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, the Glide image proxy's URL validation in src/Imaging/RemoteUrlValidator.php and … Jul 17, 2026
CVE-2026-54163 MEDIUM 4.7 secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds the Content-Security-Policy value by stitching directives with ; separators, and … Jul 17, 2026
CVE-2026-54159 CRITICAL 10.0 PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected search filters from the request URL, … Jul 17, 2026
CVE-2026-53727 UNKNOWN — css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#read_remote_file in lib/css_parser/parser.rb, and therefore load_uri! and the @import-following branch of add_block!, issued HTTP and … Jul 17, 2026