Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

52613
Total
4187
Critical
15589
High
15276
Medium
CVE ID Severity Score Description Published
CVE-2026-44752 HIGH 8.2 SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script … Jul 14, 2026
CVE-2026-44747 CRITICAL 9.9 SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to … Jul 14, 2026
CVE-2026-44745 HIGH 8.1 SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft … Jul 14, 2026
CVE-2026-27690 CRITICAL 9.1 Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. … Jul 14, 2026
CVE-2026-15621 MEDIUM 5.3 A vulnerability was detected in mosaxiv clawlet up to 0.2.10. This impacts the function read_file/write_file/edit_file of the file tools/fs_ops.go of the component File Tools. Performing … Jul 14, 2026
CVE-2026-15620 MEDIUM 6.3 A security vulnerability has been detected in mosaxiv clawlet up to 0.2.10. This affects the function tools.webFetch of the file tools/tool_web_fetch.go. Such manipulation leads to … Jul 14, 2026
CVE-2026-0487 HIGH 8.4 SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the … Jul 14, 2026
CVE-2026-15619 MEDIUM 6.3 A weakness has been identified in mosaxiv clawlet up to 0.2.10. The impacted element is the function web_fetch of the file tools/tool_web_fetch.go of the component … Jul 14, 2026
CVE-2026-15618 MEDIUM 6.3 A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. The affected element is the function guardExecCommand of the file tools/tool_exec.go of the … Jul 14, 2026
CVE-2026-58489 UNKNOWN — HedgeDoc is an open source, real-time collaborative markdown notes application. Prior to 1.11.0, the GitHub Gist export flow created an OAuth2 state value but only … Jul 13, 2026
CVE-2026-58486 UNKNOWN — HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, HedgeDoc was vulnerable to a YAML alias bomb due to unsafe … Jul 13, 2026
CVE-2026-58102 CRITICAL 9.1 Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts. When building the extension hash (via … Jul 13, 2026
CVE-2026-58101 HIGH 7.5 Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference. X509V3_EXT_d2i(ext) returns NULL when an extension's DER value fails to parse. … Jul 13, 2026
CVE-2026-57856 HIGH 8.8 Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php sanitizes the bucket name with preg_replace('/[^a-zA-Z0-9-_\\.]/','', … Jul 13, 2026
CVE-2026-57855 HIGH 8.8 Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php executes bucket commands (ls, upload, removefiles, … Jul 13, 2026
CVE-2026-15607 MEDIUM 4.3 A vulnerability was detected in tanstack db up to 0.6.8. Affected by this vulnerability is the function select of the file src/query/compiler/select.ts of the component … Jul 13, 2026
CVE-2026-15605 LOW 3.1 A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the component Artifact Integrity Validation. The … Jul 13, 2026
CVE-2026-62328 HIGH 7.5 9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to access sensitive user data by sending requests to unprotected API … Jul 13, 2026
CVE-2026-62327 CRITICAL 9.1 9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts … Jul 13, 2026
CVE-2026-62242 HIGH 8.6 Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instances with attacker-controlled healthUrl and managementUrl parameters … Jul 13, 2026
CVE-2026-62240 HIGH 7.4 CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original … Jul 13, 2026
CVE-2026-62239 MEDIUM 6.6 FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hopper/setup.py that extracts NVIDIA toolchain archives without validating … Jul 13, 2026
CVE-2026-62200 HIGH 8.8 OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport to be abused. When the affected feature … Jul 13, 2026
CVE-2026-62199 HIGH 8.8 OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter startup variables. When the affected feature is enabled and … Jul 13, 2026
CVE-2026-62198 MEDIUM 4.3 OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allows lower-trust callers to perform actions requiring stronger policy checks. … Jul 13, 2026