Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52566
Total
4174
Critical
15576
High
15266
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-44760 | MEDIUM | 4.7 | Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SAP NetWeaver Application Server ABAP reflects unsanitized input into the … | Jul 14, 2026 |
| CVE-2026-44759 | MEDIUM | 6.1 | SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and … | Jul 14, 2026 |
| CVE-2026-44753 | LOW | 3.7 | SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user … | Jul 14, 2026 |
| CVE-2026-44752 | HIGH | 8.2 | SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script … | Jul 14, 2026 |
| CVE-2026-44747 | CRITICAL | 9.9 | SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to … | Jul 14, 2026 |
| CVE-2026-44745 | HIGH | 8.1 | SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft … | Jul 14, 2026 |
| CVE-2026-27690 | CRITICAL | 9.1 | Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. … | Jul 14, 2026 |
| CVE-2026-15621 | MEDIUM | 5.3 | A vulnerability was detected in mosaxiv clawlet up to 0.2.10. This impacts the function read_file/write_file/edit_file of the file tools/fs_ops.go of the component File Tools. Performing … | Jul 14, 2026 |
| CVE-2026-15620 | MEDIUM | 6.3 | A security vulnerability has been detected in mosaxiv clawlet up to 0.2.10. This affects the function tools.webFetch of the file tools/tool_web_fetch.go. Such manipulation leads to … | Jul 14, 2026 |
| CVE-2026-0487 | HIGH | 8.4 | SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the … | Jul 14, 2026 |
| CVE-2026-15619 | MEDIUM | 6.3 | A weakness has been identified in mosaxiv clawlet up to 0.2.10. The impacted element is the function web_fetch of the file tools/tool_web_fetch.go of the component … | Jul 14, 2026 |
| CVE-2026-15618 | MEDIUM | 6.3 | A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. The affected element is the function guardExecCommand of the file tools/tool_exec.go of the … | Jul 14, 2026 |
| CVE-2026-58489 | UNKNOWN | — | HedgeDoc is an open source, real-time collaborative markdown notes application. Prior to 1.11.0, the GitHub Gist export flow created an OAuth2 state value but only … | Jul 13, 2026 |
| CVE-2026-58486 | UNKNOWN | — | HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, HedgeDoc was vulnerable to a YAML alias bomb due to unsafe … | Jul 13, 2026 |
| CVE-2026-58102 | CRITICAL | 9.1 | Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts. When building the extension hash (via … | Jul 13, 2026 |
| CVE-2026-58101 | HIGH | 7.5 | Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference. X509V3_EXT_d2i(ext) returns NULL when an extension's DER value fails to parse. … | Jul 13, 2026 |
| CVE-2026-57856 | HIGH | 8.8 | Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php sanitizes the bucket name with preg_replace('/[^a-zA-Z0-9-_\\.]/','', … | Jul 13, 2026 |
| CVE-2026-57855 | HIGH | 8.8 | Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php executes bucket commands (ls, upload, removefiles, … | Jul 13, 2026 |
| CVE-2026-15607 | MEDIUM | 4.3 | A vulnerability was detected in tanstack db up to 0.6.8. Affected by this vulnerability is the function select of the file src/query/compiler/select.ts of the component … | Jul 13, 2026 |
| CVE-2026-15605 | LOW | 3.1 | A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the component Artifact Integrity Validation. The … | Jul 13, 2026 |
| CVE-2026-62328 | HIGH | 7.5 | 9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to access sensitive user data by sending requests to unprotected API … | Jul 13, 2026 |
| CVE-2026-62327 | CRITICAL | 9.1 | 9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts … | Jul 13, 2026 |
| CVE-2026-62242 | HIGH | 8.6 | Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instances with attacker-controlled healthUrl and managementUrl parameters … | Jul 13, 2026 |
| CVE-2026-62240 | HIGH | 7.4 | CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original … | Jul 13, 2026 |
| CVE-2026-62239 | MEDIUM | 6.6 | FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hopper/setup.py that extracts NVIDIA toolchain archives without validating … | Jul 13, 2026 |