Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
53330
Total
4240
Critical
15878
High
15520
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-8800 | LOW | 2.7 | Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | Jul 08, 2026 |
| CVE-2026-8651 | LOW | 3.7 | Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | Jul 08, 2026 |
| CVE-2026-8650 | MEDIUM | 4.5 | Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | Jul 08, 2026 |
| CVE-2026-8649 | MEDIUM | 6.4 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from … | Jul 08, 2026 |
| CVE-2026-60104 | HIGH | 8.7 | Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member … | Jul 08, 2026 |
| CVE-2026-59948 | HIGH | 7.0 | Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untrusted repository other than Packagist.org … | Jul 08, 2026 |
| CVE-2026-59947 | MEDIUM | 4.7 | Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbosity, it could print … | Jul 08, 2026 |
| CVE-2026-59946 | MEDIUM | 6.1 | Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containing .. path segments can resolve … | Jul 08, 2026 |
| CVE-2026-59939 | HIGH | 7.5 | httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or … | Jul 08, 2026 |
| CVE-2026-59936 | UNKNOWN | — | pypdf is a free and open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft a PDF with a page content stream containing a … | Jul 08, 2026 |
| CVE-2026-59935 | UNKNOWN | — | pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page content stream containing a … | Jul 08, 2026 |
| CVE-2026-59822 | UNKNOWN | — | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed … | Jul 08, 2026 |
| CVE-2026-59821 | UNKNOWN | — | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create … | Jul 08, 2026 |
| CVE-2026-59820 | UNKNOWN | — | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not … | Jul 08, 2026 |
| CVE-2026-59819 | UNKNOWN | — | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment … | Jul 08, 2026 |
| CVE-2026-59807 | MEDIUM | 6.8 | Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and exfiltrate sensitive files by exploiting a missing assertSafeFileUploadPath check … | Jul 08, 2026 |
| CVE-2026-59806 | HIGH | 7.4 | Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to redirect users to arbitrary URLs or perform client-side SSRF … | Jul 08, 2026 |
| CVE-2026-59805 | MEDIUM | 6.5 | Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authenticated sellers to manipulate purchase access for other sellers' products by … | Jul 08, 2026 |
| CVE-2026-59804 | MEDIUM | 6.8 | Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfiguration vulnerability that allows unauthenticated remote attackers to hijack active … | Jul 08, 2026 |
| CVE-2026-59803 | HIGH | 7.5 | rpcx through 1.9.3, fixed in commit 047aec1, contains a denial-of-service vulnerability in protocol.Message.Decode (protocol/message.go). When a message has the compression flag set, the payload is … | Jul 08, 2026 |
| CVE-2026-59802 | HIGH | 8.2 | PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicious pushes containing … | Jul 08, 2026 |
| CVE-2026-58501 | MEDIUM | 5.9 | Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing WSDL or XSD documents, allowing transitive xsd:import, … | Jul 08, 2026 |
| CVE-2026-58254 | UNKNOWN | — | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.8, message trace destination checks were … | Jul 08, 2026 |
| CVE-2026-58253 | HIGH | 8.8 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, when no_auth_user was configured, … | Jul 08, 2026 |
| CVE-2026-58252 | MEDIUM | 6.5 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.7, and 2.11.16, an authenticated user could … | Jul 08, 2026 |