Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42739
Total
3465
Critical
12744
High
12574
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-35868 | UNKNOWN | — | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4. This flaw occurs due to insufficient validation … | Aug 27, 2026 |
| CVE-2026-34620 | MEDIUM | 5.5 | DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds write vulnerability that could lead to application denial-of-service. An attacker could leverage this … | Aug 27, 2026 |
| CVE-2026-34616 | MEDIUM | 5.5 | DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this … | Aug 27, 2026 |
| CVE-2026-30612 | UNKNOWN | — | An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker … | Aug 27, 2026 |
| CVE-2026-25250 | MEDIUM | 6.0 | EAZ EazyFix 12.9 allows a Security Feature Bypass related to a "Missing Cryptographic Step" associated with "Secure Boot disable." | Aug 27, 2026 |
| CVE-2026-19092 | CRITICAL | 9.8 | The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary … | Aug 27, 2026 |
| CVE-2026-18886 | UNKNOWN | — | ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain … | Aug 27, 2026 |
| CVE-2026-18885 | UNKNOWN | — | ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, … | Aug 27, 2026 |
| CVE-2026-18374 | MEDIUM | 4.9 | Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 … | Aug 27, 2026 |
| CVE-2026-10036 | HIGH | 8.8 | SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed … | Aug 27, 2026 |
| CVE-2026-81827 | UNKNOWN | — | Affected versions of Flowintel incorrectly attempted to validate login email addresses by calling Email(email). That does not perform WTForms field validation; it merely constructs a … | Aug 27, 2026 |
| CVE-2026-81826 | UNKNOWN | — | Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s password is changed. This means that if an attacker already possesses a … | Aug 27, 2026 |
| CVE-2026-81820 | UNKNOWN | — | Affected versions of Flowintel construct timeline HTML using attacker-controllable MISP object fields such as: * object UUID; * object name; * attribute value; * attribute … | Aug 27, 2026 |
| CVE-2026-81819 | UNKNOWN | — | Affected versions of Flowintel expose the /my_assignment/user API endpoint to any authenticated API user. The endpoint accepts a user_id parameter identifying the user whose assignments … | Aug 27, 2026 |
| CVE-2026-81818 | UNKNOWN | — | Affected versions of Flowintel contain an authorization flaw in the administrative user-edit API. The existing authorization check correctly prevented an organization administrator from editing users … | Aug 27, 2026 |
| CVE-2026-81817 | UNKNOWN | — | Affected versions of Flowintel contain an insecure direct object reference / broken object-level authorization issue across numerous task endpoints. The routes generally received both a … | Aug 27, 2026 |
| CVE-2026-81735 | CRITICAL | 10.0 | startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and … | Aug 27, 2026 |
| CVE-2026-81727 | HIGH | 7.1 | NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install … | Aug 27, 2026 |
| CVE-2026-81726 | HIGH | 7.0 | NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can … | Aug 27, 2026 |
| CVE-2026-81725 | LOW | 3.7 | NLTK before 3.10.3 contains a regular expression denial of service vulnerability in Pl196xCorpusReader that allows attackers to cause quadratic CPU consumption by supplying malformed TEI … | Aug 27, 2026 |
| CVE-2026-81724 | MEDIUM | 5.3 | NLTK before 3.10.3 contains an uncontrolled recursion vulnerability in nltk.featstruct.FeatStructReader that allows unauthenticated attackers to cause a denial of service by supplying deeply nested feature-structure … | Aug 27, 2026 |
| CVE-2026-81723 | LOW | 3.7 | NLTK versions before 3.10.3 contain a quadratic CPU exhaustion vulnerability in XMLCorpusView._read_xml_fragment() that rescans accumulated XML fragments on every 1 KiB block read. Attackers can … | Aug 27, 2026 |
| CVE-2026-81722 | HIGH | 7.5 | nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in PorterStemmer.stem(). The _is_consonant() helper walks backward over the entire … | Aug 27, 2026 |
| CVE-2026-81721 | HIGH | 7.5 | openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers can … | Aug 27, 2026 |
| CVE-2026-81720 | MEDIUM | 6.2 | openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attackers to trigger out-of-memory conditions during key derivation. Attackers with … | Aug 27, 2026 |