Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51943
Total
4127
Critical
15407
High
15098
Medium
CVE ID Severity Score Description Published
CVE-2026-7667 HIGH 8.8 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted … Jul 17, 2026
CVE-2026-7364 LOW 3.1 IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and … Jul 17, 2026
CVE-2026-63030 CRITICAL 9.8 WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query … Jul 17, 2026
CVE-2026-60137 MEDIUM 5.9 WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection … Jul 17, 2026
CVE-2026-55254 MEDIUM 4.8 NCalc is a fast, lightweight expression evaluator for .NET. Prior to 6.1.1, the factorial operator implementation in src/NCalc.Core/Helpers/MathHelper.cs permits specially crafted expressions with extremely large … Jul 17, 2026
CVE-2026-54465 UNKNOWN — websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to implement a WebSocket server on top of a … Jul 17, 2026
CVE-2026-54464 UNKNOWN — ### Impact If this library is used in tandem with the `permessage-deflate` extension, a WebSocket server or client can be made to accept messages that … Jul 17, 2026
CVE-2026-54463 UNKNOWN — websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket protocol in websocket-driver include a length header that … Jul 17, 2026
CVE-2026-54171 MEDIUM 6.5 Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip additional sensitive headers when following redirects and … Jul 17, 2026
CVE-2026-52199 UNKNOWN — An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component Jul 17, 2026
CVE-2026-51833 UNKNOWN — Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can enumerate internal services (ports) or expose … Jul 17, 2026
CVE-2026-50289 UNKNOWN — systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is vulnerable to OS command injection through the Debian/Ubuntu … Jul 17, 2026
CVE-2026-50197 UNKNOWN — Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipper's OpenPolicyAgent integration silently bypasses request-body inspection on HTTP/1.1 Transfer-Encoding: chunked … Jul 17, 2026
CVE-2026-50163 HIGH 7.1 oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relative to the extract base but … Jul 17, 2026
CVE-2026-50162 UNKNOWN — oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a lexical filepath.Rel check for workingDir and does not … Jul 17, 2026
CVE-2026-50151 HIGH 7.5 oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and … Jul 17, 2026
CVE-2026-4942 MEDIUM 5.9 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Transport Layer Security (TLS) … Jul 17, 2026
CVE-2026-4938 MEDIUM 6.5 IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and … Jul 17, 2026
CVE-2026-49852 UNKNOWN — joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.jwt.decode accepts attacker-forged HMAC-signed … Jul 17, 2026
CVE-2026-49834 MEDIUM 5.9 sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) counts verified witnesses per entry … Jul 17, 2026
CVE-2026-49284 HIGH 7.1 SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. Prior to 2.4.7 and 2.5.2, SimpleSAMLphp's SAML SP ACS path does not enforce the IdP selected … Jul 17, 2026
CVE-2026-48978 UNKNOWN — oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating … Jul 17, 2026
CVE-2026-48819 MEDIUM 4.8 Hey API is an ecosystem for turning API specifications into production-ready code. Prior to 0.97.3, dist/clients/core/params.ts ships a runtime template copied into generated SDKs as … Jul 17, 2026
CVE-2026-48504 MEDIUM 5.3 OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_context in opentelemetry_sdk did not enforce W3C Baggage size limits before parsing an inbound … Jul 17, 2026
CVE-2026-48373 HIGH 7.8 Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation … Jul 17, 2026