Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42400
Total
3455
Critical
12534
High
12466
Medium
CVE ID Severity Score Description Published
CVE-2026-38638 HIGH 7.5 An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input. Aug 28, 2026
CVE-2026-38636 HIGH 7.5 An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input. Aug 28, 2026
CVE-2026-38093 LOW 3.3 file_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.10, is vulnerable to path traversal (CWE-22) in its Android implementation. The openFileStream() method in FileUtils.kt uses … Aug 28, 2026
CVE-2026-37751 CRITICAL 9.8 An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input. Aug 28, 2026
CVE-2026-37736 HIGH 7.5 An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers to cause a Denial of Service (DoS) via a crafted input. Aug 28, 2026
CVE-2026-37710 MEDIUM 6.1 Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacker to execute arbitrary code via the site navigation custom URL function Aug 28, 2026
CVE-2026-37237 HIGH 7.5 vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMediaIO.fetch_audio and AsyncMediaIO.fetch_image functions in multimodal/inputs.py … Aug 28, 2026
CVE-2026-37236 UNKNOWN grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with … Aug 28, 2026
CVE-2026-19412 UNKNOWN This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical … Aug 28, 2026
CVE-2026-15603 MEDIUM 5.3 morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize … Aug 28, 2026
CVE-2026-14942 UNKNOWN Rejected reason: This CVE ID was assigned to a reported vulnerability in the Customer Reviews for WooCommerce WordPress plugin and was never published. The report … Aug 28, 2026
CVE-2026-13761 UNKNOWN Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial … Aug 28, 2026
CVE-2026-82261 HIGH 7.5 SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulnerability in form deserialization. An attacker can send … Aug 28, 2026
CVE-2026-82260 HIGH 7.5 SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form … Aug 28, 2026
CVE-2026-82259 HIGH 7.5 SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions … Aug 28, 2026
CVE-2026-82258 UNKNOWN SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to merge under a single request … Aug 28, 2026
CVE-2026-82257 MEDIUM 4.3 SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can … Aug 28, 2026
CVE-2026-82256 MEDIUM 5.3 SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sending large payloads. Repeated exploitation … Aug 28, 2026
CVE-2026-82255 MEDIUM 6.8 gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credentials are sent to attacker-controlled servers after HTTP redirects. … Aug 28, 2026
CVE-2026-82254 HIGH 7.5 gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data … Aug 28, 2026
CVE-2026-82253 HIGH 7.5 gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the … Aug 28, 2026
CVE-2026-82252 HIGH 7.5 gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious … Aug 28, 2026
CVE-2026-82251 HIGH 7.5 gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names … Aug 28, 2026
CVE-2026-82250 MEDIUM 6.5 gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing side-band packet lines with empty payloads. A malicious … Aug 28, 2026
CVE-2026-82249 LOW 3.1 gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns to … Aug 28, 2026