Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52613
Total
4187
Critical
15589
High
15276
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-44752 | HIGH | 8.2 | SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script … | Jul 14, 2026 |
| CVE-2026-44747 | CRITICAL | 9.9 | SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to … | Jul 14, 2026 |
| CVE-2026-44745 | HIGH | 8.1 | SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft … | Jul 14, 2026 |
| CVE-2026-27690 | CRITICAL | 9.1 | Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. … | Jul 14, 2026 |
| CVE-2026-15621 | MEDIUM | 5.3 | A vulnerability was detected in mosaxiv clawlet up to 0.2.10. This impacts the function read_file/write_file/edit_file of the file tools/fs_ops.go of the component File Tools. Performing … | Jul 14, 2026 |
| CVE-2026-15620 | MEDIUM | 6.3 | A security vulnerability has been detected in mosaxiv clawlet up to 0.2.10. This affects the function tools.webFetch of the file tools/tool_web_fetch.go. Such manipulation leads to … | Jul 14, 2026 |
| CVE-2026-0487 | HIGH | 8.4 | SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the … | Jul 14, 2026 |
| CVE-2026-15619 | MEDIUM | 6.3 | A weakness has been identified in mosaxiv clawlet up to 0.2.10. The impacted element is the function web_fetch of the file tools/tool_web_fetch.go of the component … | Jul 14, 2026 |
| CVE-2026-15618 | MEDIUM | 6.3 | A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. The affected element is the function guardExecCommand of the file tools/tool_exec.go of the … | Jul 14, 2026 |
| CVE-2026-58489 | UNKNOWN | — | HedgeDoc is an open source, real-time collaborative markdown notes application. Prior to 1.11.0, the GitHub Gist export flow created an OAuth2 state value but only … | Jul 13, 2026 |
| CVE-2026-58486 | UNKNOWN | — | HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, HedgeDoc was vulnerable to a YAML alias bomb due to unsafe … | Jul 13, 2026 |
| CVE-2026-58102 | CRITICAL | 9.1 | Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts. When building the extension hash (via … | Jul 13, 2026 |
| CVE-2026-58101 | HIGH | 7.5 | Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference. X509V3_EXT_d2i(ext) returns NULL when an extension's DER value fails to parse. … | Jul 13, 2026 |
| CVE-2026-57856 | HIGH | 8.8 | Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php sanitizes the bucket name with preg_replace('/[^a-zA-Z0-9-_\\.]/','', … | Jul 13, 2026 |
| CVE-2026-57855 | HIGH | 8.8 | Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api() method in modules/System/Controller/Buckets.php executes bucket commands (ls, upload, removefiles, … | Jul 13, 2026 |
| CVE-2026-15607 | MEDIUM | 4.3 | A vulnerability was detected in tanstack db up to 0.6.8. Affected by this vulnerability is the function select of the file src/query/compiler/select.ts of the component … | Jul 13, 2026 |
| CVE-2026-15605 | LOW | 3.1 | A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download in the library wandb/sdk/lib/hashutil.py of the component Artifact Integrity Validation. The … | Jul 13, 2026 |
| CVE-2026-62328 | HIGH | 7.5 | 9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to access sensitive user data by sending requests to unprotected API … | Jul 13, 2026 |
| CVE-2026-62327 | CRITICAL | 9.1 | 9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts … | Jul 13, 2026 |
| CVE-2026-62242 | HIGH | 8.6 | Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instances with attacker-controlled healthUrl and managementUrl parameters … | Jul 13, 2026 |
| CVE-2026-62240 | HIGH | 7.4 | CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original … | Jul 13, 2026 |
| CVE-2026-62239 | MEDIUM | 6.6 | FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hopper/setup.py that extracts NVIDIA toolchain archives without validating … | Jul 13, 2026 |
| CVE-2026-62200 | HIGH | 8.8 | OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport to be abused. When the affected feature … | Jul 13, 2026 |
| CVE-2026-62199 | HIGH | 8.8 | OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter startup variables. When the affected feature is enabled and … | Jul 13, 2026 |
| CVE-2026-62198 | MEDIUM | 4.3 | OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allows lower-trust callers to perform actions requiring stronger policy checks. … | Jul 13, 2026 |