Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52113
Total
4140
Critical
15446
High
15158
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-61684 | UNKNOWN | — | FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse-call endpoints under /api/invoke/* authenticate only by verifying a JWT signed with INVOKE_TOKEN_SECRET, … | Jul 15, 2026 |
| CVE-2026-61646 | UNKNOWN | — | FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta5, FastGPT's shared SSRF guard validates only the initial request URL before handing the request to … | Jul 15, 2026 |
| CVE-2026-61644 | HIGH | 7.7 | FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, the POST /api/core/chat/record/getCollectionQuote endpoint authenticates the caller's chat and collection context, but the initialId … | Jul 15, 2026 |
| CVE-2026-61613 | UNKNOWN | — | Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled … | Jul 15, 2026 |
| CVE-2026-60065 | LOW | 3.7 | When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the … | Jul 15, 2026 |
| CVE-2026-60062 | MEDIUM | 6.4 | The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The … | Jul 15, 2026 |
| CVE-2026-59762 | HIGH | 7.5 | When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Impact: System performance can degrade … | Jul 15, 2026 |
| CVE-2026-56434 | MEDIUM | 6.5 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering … | Jul 15, 2026 |
| CVE-2026-55723 | HIGH | 8.3 | When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress … | Jul 15, 2026 |
| CVE-2026-54563 | HIGH | 7.1 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV account rooted at a configured folder can send paths such … | Jul 15, 2026 |
| CVE-2026-54562 | MEDIUM | 6.5 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote download workflow accepts user-supplied URLs at POST /api/v4/workflow/download and passes them … | Jul 15, 2026 |
| CVE-2026-54560 | HIGH | 7.6 | Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's OAuth access tokens are issued without the OAuth client_id claim, so … | Jul 15, 2026 |
| CVE-2026-52865 | MEDIUM | 6.5 | When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause … | Jul 15, 2026 |
| CVE-2026-42533 | HIGH | 8.1 | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex … | Jul 15, 2026 |
| CVE-2026-33213 | MEDIUM | 6.1 | Redash is a package for data visualization and sharing. From 5.0.2 to 26.3.0, the get_next_path() function in Redash's authentication module stripped the scheme and netloc … | Jul 15, 2026 |
| CVE-2026-62175 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-60091. Reason: This candidate is a duplicate of CVE-2026-60091. Notes: All CVE users … | Jul 15, 2026 |
| CVE-2026-59838 | MEDIUM | 5.9 | A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.2.0 through … | Jul 15, 2026 |
| CVE-2026-43637 | CRITICAL | 9.1 | Cornac before 2.6.0 contains a path traversal (Tar Slip) vulnerability that allows attackers to write arbitrary files outside the intended cache directory by supplying a … | Jul 15, 2026 |
| CVE-2026-58559 | MEDIUM | 6.5 | DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availability. | Jul 15, 2026 |
| CVE-2026-58558 | HIGH | 7.8 | Permission control vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Jul 15, 2026 |
| CVE-2026-58557 | MEDIUM | 4.8 | Design defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerability may affect availability. | Jul 15, 2026 |
| CVE-2026-58556 | MEDIUM | 5.1 | Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect availability. | Jul 15, 2026 |
| CVE-2026-58555 | MEDIUM | 6.6 | Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect availability. | Jul 15, 2026 |
| CVE-2026-58554 | MEDIUM | 6.6 | Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Jul 15, 2026 |
| CVE-2026-58553 | MEDIUM | 4.0 | Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | Jul 15, 2026 |