Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

53330
Total
4240
Critical
15878
High
15520
Medium
CVE ID Severity Score Description Published
CVE-2026-8800 LOW 2.7 Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. Jul 08, 2026
CVE-2026-8651 LOW 3.7 Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. Jul 08, 2026
CVE-2026-8650 MEDIUM 4.5 Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. Jul 08, 2026
CVE-2026-8649 MEDIUM 6.4 Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from … Jul 08, 2026
CVE-2026-60104 HIGH 8.7 Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member … Jul 08, 2026
CVE-2026-59948 HIGH 7.0 Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org … Jul 08, 2026
CVE-2026-59947 MEDIUM 4.7 Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbosity, it could print … Jul 08, 2026
CVE-2026-59946 MEDIUM 6.1 Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve … Jul 08, 2026
CVE-2026-59939 HIGH 7.5 httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or … Jul 08, 2026
CVE-2026-59936 UNKNOWN — pypdf is a free and open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft a PDF with a page content stream containing a … Jul 08, 2026
CVE-2026-59935 UNKNOWN — pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a … Jul 08, 2026
CVE-2026-59822 UNKNOWN — LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed … Jul 08, 2026
CVE-2026-59821 UNKNOWN — LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create … Jul 08, 2026
CVE-2026-59820 UNKNOWN — LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not … Jul 08, 2026
CVE-2026-59819 UNKNOWN — LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment … Jul 08, 2026
CVE-2026-59807 MEDIUM 6.8 Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and exfiltrate sensitive files by exploiting a missing assertSafeFileUploadPath check … Jul 08, 2026
CVE-2026-59806 HIGH 7.4 Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to redirect users to arbitrary URLs or perform client-side SSRF … Jul 08, 2026
CVE-2026-59805 MEDIUM 6.5 Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authenticated sellers to manipulate purchase access for other sellers' products by … Jul 08, 2026
CVE-2026-59804 MEDIUM 6.8 Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfiguration vulnerability that allows unauthenticated remote attackers to hijack active … Jul 08, 2026
CVE-2026-59803 HIGH 7.5 rpcx through 1.9.3, fixed in commit 047aec1, contains a denial-of-service vulnerability in protocol.Message.Decode (protocol/message.go). When a message has the compression flag set, the payload is … Jul 08, 2026
CVE-2026-59802 HIGH 8.2 PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicious pushes containing … Jul 08, 2026
CVE-2026-58501 MEDIUM 5.9 Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing WSDL or XSD documents, allowing transitive xsd:import, … Jul 08, 2026
CVE-2026-58254 UNKNOWN — NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.8, message trace destination checks were … Jul 08, 2026
CVE-2026-58253 HIGH 8.8 NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, when no_auth_user was configured, … Jul 08, 2026
CVE-2026-58252 MEDIUM 6.5 NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user could … Jul 08, 2026