Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51943
Total
4127
Critical
15407
High
15098
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-7667 | HIGH | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted … | Jul 17, 2026 |
| CVE-2026-7364 | LOW | 3.1 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and … | Jul 17, 2026 |
| CVE-2026-63030 | CRITICAL | 9.8 | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query … | Jul 17, 2026 |
| CVE-2026-60137 | MEDIUM | 5.9 | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection … | Jul 17, 2026 |
| CVE-2026-55254 | MEDIUM | 4.8 | NCalc is a fast, lightweight expression evaluator for .NET. Prior to 6.1.1, the factorial operator implementation in src/NCalc.Core/Helpers/MathHelper.cs permits specially crafted expressions with extremely large … | Jul 17, 2026 |
| CVE-2026-54465 | UNKNOWN | — | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to implement a WebSocket server on top of a … | Jul 17, 2026 |
| CVE-2026-54464 | UNKNOWN | — | ### Impact If this library is used in tandem with the `permessage-deflate` extension, a WebSocket server or client can be made to accept messages that … | Jul 17, 2026 |
| CVE-2026-54463 | UNKNOWN | — | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket protocol in websocket-driver include a length header that … | Jul 17, 2026 |
| CVE-2026-54171 | MEDIUM | 6.5 | Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip additional sensitive headers when following redirects and … | Jul 17, 2026 |
| CVE-2026-52199 | UNKNOWN | — | An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component | Jul 17, 2026 |
| CVE-2026-51833 | UNKNOWN | — | Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can enumerate internal services (ports) or expose … | Jul 17, 2026 |
| CVE-2026-50289 | UNKNOWN | — | systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is vulnerable to OS command injection through the Debian/Ubuntu … | Jul 17, 2026 |
| CVE-2026-50197 | UNKNOWN | — | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipper's OpenPolicyAgent integration silently bypasses request-body inspection on HTTP/1.1 Transfer-Encoding: chunked … | Jul 17, 2026 |
| CVE-2026-50163 | HIGH | 7.1 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relative to the extract base but … | Jul 17, 2026 |
| CVE-2026-50162 | UNKNOWN | — | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a lexical filepath.Rel check for workingDir and does not … | Jul 17, 2026 |
| CVE-2026-50151 | HIGH | 7.5 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and … | Jul 17, 2026 |
| CVE-2026-4942 | MEDIUM | 5.9 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Transport Layer Security (TLS) … | Jul 17, 2026 |
| CVE-2026-4938 | MEDIUM | 6.5 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and … | Jul 17, 2026 |
| CVE-2026-49852 | UNKNOWN | — | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.jwt.decode accepts attacker-forged HMAC-signed … | Jul 17, 2026 |
| CVE-2026-49834 | MEDIUM | 5.9 | sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) counts verified witnesses per entry … | Jul 17, 2026 |
| CVE-2026-49284 | HIGH | 7.1 | SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. Prior to 2.4.7 and 2.5.2, SimpleSAMLphp's SAML SP ACS path does not enforce the IdP selected … | Jul 17, 2026 |
| CVE-2026-48978 | UNKNOWN | — | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating … | Jul 17, 2026 |
| CVE-2026-48819 | MEDIUM | 4.8 | Hey API is an ecosystem for turning API specifications into production-ready code. Prior to 0.97.3, dist/clients/core/params.ts ships a runtime template copied into generated SDKs as … | Jul 17, 2026 |
| CVE-2026-48504 | MEDIUM | 5.3 | OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_context in opentelemetry_sdk did not enforce W3C Baggage size limits before parsing an inbound … | Jul 17, 2026 |
| CVE-2026-48373 | HIGH | 7.8 | Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation … | Jul 17, 2026 |