Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

52113
Total
4140
Critical
15446
High
15158
Medium
CVE ID Severity Score Description Published
CVE-2026-62843 MEDIUM 6.8 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's … Jul 15, 2026
CVE-2026-62685 HIGH 8.1 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser builds … Jul 15, 2026
CVE-2026-62683 LOW 3.1 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser can … Jul 15, 2026
CVE-2026-61828 UNKNOWN — Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and 26.05 channel fixes, the … Jul 15, 2026
CVE-2026-61605 UNKNOWN — Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-58655. Reason: This candidate is a duplicate of CVE-2026-58655. Notes: All CVE users … Jul 15, 2026
CVE-2026-61371 HIGH 7.5 Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/overwrite of the symlink target. The destructive effect … Jul 15, 2026
CVE-2026-60005 HIGH 8.2 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when … Jul 15, 2026
CVE-2026-55242 HIGH 8.8 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can … Jul 15, 2026
CVE-2026-50148 CRITICAL 10.0 Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with … Jul 15, 2026
CVE-2026-50147 HIGH 7.6 Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4, an attacker who can configure a Metabase … Jul 15, 2026
CVE-2026-47164 HIGH 7.7 Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only for new-user creation and … Jul 15, 2026
CVE-2026-47160 MEDIUM 5.8 Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png endpoint used src/http_client.rs checks including should_block_address() and post_resolve() that missed decimal, hexadecimal, … Jul 15, 2026
CVE-2026-47159 UNKNOWN — Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organization-related SSO metadata including organizationIdentifier values for … Jul 15, 2026
CVE-2026-47158 HIGH 8.3 Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /connect/authorize … Jul 15, 2026
CVE-2026-46709 HIGH 7.8 Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths from tabby-electron/src/pathDrop.ts into the active shell without neutralizing … Jul 15, 2026
CVE-2026-45806 HIGH 7.7 Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's remote image import passed the user-controlled url from frontend/src/app/main/data/workspace/media.cljs into … Jul 15, 2026
CVE-2026-45805 HIGH 8.8 Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/server/src/ReplServer.ts bound the ReplServer to 0.0.0.0:4403 and exposed an … Jul 15, 2026
CVE-2026-45150 UNKNOWN — Zen is a firefox-based browser. Prior to 1.19.13b, Zen Browser did not provide a persistent, clearly visible security notification when a webpage entered fullscreen mode, … Jul 15, 2026
CVE-2026-44986 CRITICAL 9.9 Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing profile … Jul 15, 2026
CVE-2026-41580 MEDIUM 6.1 Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, Stirling-PDF's /get-info-on-pdf endpoint rendered PDF Title and Author … Jul 15, 2026
CVE-2026-62294 UNKNOWN — Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed … Jul 15, 2026
CVE-2026-61836 HIGH 8.6 Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching is enabled, the cache-key derivation in … Jul 15, 2026
CVE-2026-61835 HIGH 7.7 Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on Directus's file-import-from-URL feature can be … Jul 15, 2026
CVE-2026-61740 UNKNOWN — LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUNTS unset, X-API-Key protection can be bypassed … Jul 15, 2026
CVE-2026-61736 CRITICAL 9.3 LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combined with allow_credentials=True in lightrag/api/lightrag_server.py, causing Starlette CORSMiddleware to effectively … Jul 15, 2026