Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42739
Total
3465
Critical
12744
High
12574
Medium
CVE ID Severity Score Description Published
CVE-2026-35868 UNKNOWN A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4. This flaw occurs due to insufficient validation … Aug 27, 2026
CVE-2026-34620 MEDIUM 5.5 DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds write vulnerability that could lead to application denial-of-service. An attacker could leverage this … Aug 27, 2026
CVE-2026-34616 MEDIUM 5.5 DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this … Aug 27, 2026
CVE-2026-30612 UNKNOWN An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker … Aug 27, 2026
CVE-2026-25250 MEDIUM 6.0 EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot disable." Aug 27, 2026
CVE-2026-19092 CRITICAL 9.8 The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary … Aug 27, 2026
CVE-2026-18886 UNKNOWN ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain … Aug 27, 2026
CVE-2026-18885 UNKNOWN ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, … Aug 27, 2026
CVE-2026-18374 MEDIUM 4.9 Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 … Aug 27, 2026
CVE-2026-10036 HIGH 8.8 SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed … Aug 27, 2026
CVE-2026-81827 UNKNOWN Affected versions of Flowintel incorrectly attempted to validate login email addresses by calling Email(email). That does not perform WTForms field validation; it merely constructs a … Aug 27, 2026
CVE-2026-81826 UNKNOWN Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s password is changed. This means that if an attacker already possesses a … Aug 27, 2026
CVE-2026-81820 UNKNOWN Affected versions of Flowintel construct timeline HTML using attacker-controllable MISP object fields such as: * object UUID; * object name; * attribute value; * attribute … Aug 27, 2026
CVE-2026-81819 UNKNOWN Affected versions of Flowintel expose the /my_assignment/user API endpoint to any authenticated API user. The endpoint accepts a user_id parameter identifying the user whose assignments … Aug 27, 2026
CVE-2026-81818 UNKNOWN Affected versions of Flowintel contain an authorization flaw in the administrative user-edit API. The existing authorization check correctly prevented an organization administrator from editing users … Aug 27, 2026
CVE-2026-81817 UNKNOWN Affected versions of Flowintel contain an insecure direct object reference / broken object-level authorization issue across numerous task endpoints. The routes generally received both a … Aug 27, 2026
CVE-2026-81735 CRITICAL 10.0 startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and … Aug 27, 2026
CVE-2026-81727 HIGH 7.1 NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install … Aug 27, 2026
CVE-2026-81726 HIGH 7.0 NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can … Aug 27, 2026
CVE-2026-81725 LOW 3.7 NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying malformed TEI … Aug 27, 2026
CVE-2026-81724 MEDIUM 5.3 NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure … Aug 27, 2026
CVE-2026-81723 LOW 3.7 NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read. Attackers can … Aug 27, 2026
CVE-2026-81722 HIGH 7.5 nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire … Aug 27, 2026
CVE-2026-81721 HIGH 7.5 openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can … Aug 27, 2026
CVE-2026-81720 MEDIUM 6.2 openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation. Attackers with … Aug 27, 2026