Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

52113
Total
4140
Critical
15446
High
15158
Medium
CVE ID Severity Score Description Published
CVE-2026-54443 UNKNOWN — Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssFeed.vue does not sanitize RSS item link values before rendering … Jul 15, 2026
CVE-2026-49988 UNKNOWN — Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_output and read_repomix_output flow can register and read … Jul 15, 2026
CVE-2026-49987 UNKNOWN — Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, src/core/git/gitCommand.ts execGitShallowClone passes the --remote-branch value directly to git fetch and git … Jul 15, 2026
CVE-2026-46485 HIGH 8.2 Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to … Jul 15, 2026
CVE-2026-46421 UNKNOWN — The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that … Jul 15, 2026
CVE-2026-26032 MEDIUM 5.4 The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repackaging … Jul 15, 2026
CVE-2026-15895 HIGH 7.8 OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent attackers to execute arbitrary commands via crafted package … Jul 15, 2026
CVE-2026-15746 MEDIUM 6.5 Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including … Jul 15, 2026
CVE-2026-12997 HIGH 7.5 The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter. This … Jul 15, 2026
CVE-2026-8055 UNKNOWN — Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-48866. Reason: This candidate is a reservation duplicate of CVE-2026-48866. Notes: All CVE … Jul 15, 2026
CVE-2026-62948 CRITICAL 9.6 OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefiles.c … Jul 15, 2026
CVE-2026-62389 HIGH 7.5 ws before 8.21.1 contains a memory exhaustion vulnerability in lib/receiver.js where the fragment guard only triggers when fragment count reaches maxFragments, allowing attackers to exhaust … Jul 15, 2026
CVE-2026-61643 MEDIUM 5.9 FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can save a workflow node that points to another user's … Jul 15, 2026
CVE-2026-59258 HIGH 8.3 immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that allows shared album editors to modify member roles without owner-only … Jul 15, 2026
CVE-2026-59255 HIGH 7.1 BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes API endpoints that allows any authenticated user to modify the … Jul 15, 2026
CVE-2026-58660 HIGH 8.1 Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the attacker-supplied project_id … Jul 15, 2026
CVE-2026-58659 HIGH 7.8 PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names … Jul 15, 2026
CVE-2026-58658 HIGH 8.2 GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to access sensitive inference logs and modify worker … Jul 15, 2026
CVE-2026-56687 HIGH 7.8 Dell ThinOS 10, versions prior to 2605_10.2100, contain an Obsolete Feature in UI vulnerability. A low privileged attacker with local access could potentially exploit this … Jul 15, 2026
CVE-2026-56087 MEDIUM 6.1 Dell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism Failure vulnerability. An attacker with physical access could potentially exploit this vulnerability, leading to … Jul 15, 2026
CVE-2026-53518 UNKNOWN — Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint for the authorization_code grant redeems a … Jul 15, 2026
CVE-2026-53517 HIGH 8.1 Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refresh_token grant performs a … Jul 15, 2026
CVE-2026-53516 HIGH 8.3 Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback auto-link gate in handleOAuthUserInfo accepts implicit account linking … Jul 15, 2026
CVE-2026-53515 HIGH 7.1 Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/sso plugin's POST /sso/register endpoint lets any organization member attach … Jul 15, 2026
CVE-2026-53514 HIGH 7.7 Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when invitation IDs can be obtained outside … Jul 15, 2026