Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

52066
Total
4132
Critical
15433
High
15137
Medium
CVE ID Severity Score Description Published
CVE-2026-44595 MEDIUM 4.3 Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required … Jul 16, 2026
CVE-2026-3031 UNKNOWN — Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg 0.9.0 that was last updated in 2004. Epeg … Jul 16, 2026
CVE-2026-14371 UNKNOWN — The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when … Jul 16, 2026
CVE-2026-13401 HIGH 7.5 XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor … Jul 16, 2026
CVE-2026-13397 HIGH 7.5 HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor … Jul 16, 2026
CVE-2026-13104 HIGH 7.3 A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary … Jul 16, 2026
CVE-2026-13103 HIGH 7.3 A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to … Jul 16, 2026
CVE-2026-10590 MEDIUM 4.4 A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrarily trigger a System Management Interrupt handler. Jul 16, 2026
CVE-2026-10589 MEDIUM 6.0 A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode. Jul 16, 2026
CVE-2026-10588 MEDIUM 4.4 A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory. Jul 16, 2026
CVE-2026-10587 MEDIUM 6.0 A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode. Jul 16, 2026
CVE-2025-45870 UNKNOWN — LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated user to exploit path … Jul 16, 2026
CVE-2026-63082 MEDIUM 5.4 Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers with Agent-level privileges to manipulate the … Jul 16, 2026
CVE-2026-63081 MEDIUM 5.4 Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious … Jul 16, 2026
CVE-2026-59867 HIGH 7.1 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local … Jul 16, 2026
CVE-2026-59866 UNKNOWN — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as … Jul 16, 2026
CVE-2026-59865 UNKNOWN — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version values from an OpenAPI … Jul 16, 2026
CVE-2026-59864 UNKNOWN — Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_template.file … Jul 16, 2026
CVE-2026-57206 HIGH 8.6 SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin validation routes in application/single_app/plugin_validation_endpoint.py, including … Jul 16, 2026
CVE-2026-57205 MEDIUM 4.3 SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> … Jul 16, 2026
CVE-2026-55440 MEDIUM 6.5 Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/server/ws/handler.py called get_or_create_session in ufo/server/services/session_manager.py without owner_client_id, … Jul 16, 2026
CVE-2026-54733 UNKNOWN — The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and … Jul 16, 2026
CVE-2026-54568 MEDIUM 4.3 Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a client connected to the UFO WebSocket server as a … Jul 16, 2026
CVE-2026-53598 HIGH 7.5 Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that resolved … Jul 16, 2026
CVE-2026-53597 UNKNOWN — Prompty is a markdown file format (.prompty) for LLM prompts. From 2.0.0-alpha.1 until 2.0.0-beta.3, the @prompty/core TypeScript loader in runtime/typescript/packages/core/src/core/loader.ts used gray-matter without overriding executable … Jul 16, 2026