Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52113
Total
4140
Critical
15446
High
15158
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-54443 | UNKNOWN | — | Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssFeed.vue does not sanitize RSS item link values before rendering … | Jul 15, 2026 |
| CVE-2026-49988 | UNKNOWN | — | Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_output and read_repomix_output flow can register and read … | Jul 15, 2026 |
| CVE-2026-49987 | UNKNOWN | — | Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, src/core/git/gitCommand.ts execGitShallowClone passes the --remote-branch value directly to git fetch and git … | Jul 15, 2026 |
| CVE-2026-46485 | HIGH | 8.2 | Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to … | Jul 15, 2026 |
| CVE-2026-46421 | UNKNOWN | — | The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that … | Jul 15, 2026 |
| CVE-2026-26032 | MEDIUM | 5.4 | The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repackaging … | Jul 15, 2026 |
| CVE-2026-15895 | HIGH | 7.8 | OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent attackers to execute arbitrary commands via crafted package … | Jul 15, 2026 |
| CVE-2026-15746 | MEDIUM | 6.5 | Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including … | Jul 15, 2026 |
| CVE-2026-12997 | HIGH | 7.5 | The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter. This … | Jul 15, 2026 |
| CVE-2026-8055 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-48866. Reason: This candidate is a reservation duplicate of CVE-2026-48866. Notes: All CVE … | Jul 15, 2026 |
| CVE-2026-62948 | CRITICAL | 9.6 | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefiles.c … | Jul 15, 2026 |
| CVE-2026-62389 | HIGH | 7.5 | ws before 8.21.1 contains a memory exhaustion vulnerability in lib/receiver.js where the fragment guard only triggers when fragment count reaches maxFragments, allowing attackers to exhaust … | Jul 15, 2026 |
| CVE-2026-61643 | MEDIUM | 5.9 | FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can save a workflow node that points to another user's … | Jul 15, 2026 |
| CVE-2026-59258 | HIGH | 8.3 | immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles without owner-only … | Jul 15, 2026 |
| CVE-2026-59255 | HIGH | 7.1 | BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to modify the … | Jul 15, 2026 |
| CVE-2026-58660 | HIGH | 8.1 | Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the attacker-supplied project_id … | Jul 15, 2026 |
| CVE-2026-58659 | HIGH | 7.8 | PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names … | Jul 15, 2026 |
| CVE-2026-58658 | HIGH | 8.2 | GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to access sensitive inference logs and modify worker … | Jul 15, 2026 |
| CVE-2026-56687 | HIGH | 7.8 | Dell ThinOS 10, versions prior to 2605_10.2100, contain an Obsolete Feature in UI vulnerability. A low privileged attacker with local access could potentially exploit this … | Jul 15, 2026 |
| CVE-2026-56087 | MEDIUM | 6.1 | Dell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism Failure vulnerability. An attacker with physical access could potentially exploit this vulnerability, leading to … | Jul 15, 2026 |
| CVE-2026-53518 | UNKNOWN | — | Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint for the authorization_code grant redeems a … | Jul 15, 2026 |
| CVE-2026-53517 | HIGH | 8.1 | Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refresh_token grant performs a … | Jul 15, 2026 |
| CVE-2026-53516 | HIGH | 8.3 | Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback auto-link gate in handleOAuthUserInfo accepts implicit account linking … | Jul 15, 2026 |
| CVE-2026-53515 | HIGH | 7.1 | Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/sso plugin's POST /sso/register endpoint lets any organization member attach … | Jul 15, 2026 |
| CVE-2026-53514 | HIGH | 7.7 | Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtained outside … | Jul 15, 2026 |