Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52066
Total
4132
Critical
15433
High
15137
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-44595 | MEDIUM | 4.3 | Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required … | Jul 16, 2026 |
| CVE-2026-3031 | UNKNOWN | — | Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg 0.9.0 that was last updated in 2004. Epeg … | Jul 16, 2026 |
| CVE-2026-14371 | UNKNOWN | — | The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when … | Jul 16, 2026 |
| CVE-2026-13401 | HIGH | 7.5 | XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor … | Jul 16, 2026 |
| CVE-2026-13397 | HIGH | 7.5 | HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor … | Jul 16, 2026 |
| CVE-2026-13104 | HIGH | 7.3 | A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary … | Jul 16, 2026 |
| CVE-2026-13103 | HIGH | 7.3 | A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to … | Jul 16, 2026 |
| CVE-2026-10590 | MEDIUM | 4.4 | A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrarily trigger a System Management Interrupt handler. | Jul 16, 2026 |
| CVE-2026-10589 | MEDIUM | 6.0 | A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode. | Jul 16, 2026 |
| CVE-2026-10588 | MEDIUM | 4.4 | A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory. | Jul 16, 2026 |
| CVE-2026-10587 | MEDIUM | 6.0 | A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode. | Jul 16, 2026 |
| CVE-2025-45870 | UNKNOWN | — | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated user to exploit path … | Jul 16, 2026 |
| CVE-2026-63082 | MEDIUM | 5.4 | Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers with Agent-level privileges to manipulate the … | Jul 16, 2026 |
| CVE-2026-63081 | MEDIUM | 5.4 | Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious … | Jul 16, 2026 |
| CVE-2026-59867 | HIGH | 7.1 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local … | Jul 16, 2026 |
| CVE-2026-59866 | UNKNOWN | — | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as … | Jul 16, 2026 |
| CVE-2026-59865 | UNKNOWN | — | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version values from an OpenAPI … | Jul 16, 2026 |
| CVE-2026-59864 | UNKNOWN | — | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_template.file … | Jul 16, 2026 |
| CVE-2026-57206 | HIGH | 8.6 | SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin validation routes in application/single_app/plugin_validation_endpoint.py, including … | Jul 16, 2026 |
| CVE-2026-57205 | MEDIUM | 4.3 | SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> … | Jul 16, 2026 |
| CVE-2026-55440 | MEDIUM | 6.5 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/server/ws/handler.py called get_or_create_session in ufo/server/services/session_manager.py without owner_client_id, … | Jul 16, 2026 |
| CVE-2026-54733 | UNKNOWN | — | The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and … | Jul 16, 2026 |
| CVE-2026-54568 | MEDIUM | 4.3 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a client connected to the UFO WebSocket server as a … | Jul 16, 2026 |
| CVE-2026-53598 | HIGH | 7.5 | Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that resolved … | Jul 16, 2026 |
| CVE-2026-53597 | UNKNOWN | — | Prompty is a markdown file format (.prompty) for LLM prompts. From 2.0.0-alpha.1 until 2.0.0-beta.3, the @prompty/core TypeScript loader in runtime/typescript/packages/core/src/core/loader.ts used gray-matter without overriding executable … | Jul 16, 2026 |