Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42775
Total
3467
Critical
12772
High
12580
Medium
CVE ID Severity Score Description Published
CVE-2026-81699 HIGH 7.5 openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during … Aug 27, 2026
CVE-2026-81698 HIGH 7.5 openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can … Aug 27, 2026
CVE-2026-81697 MEDIUM 5.5 openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative configuration file resolution flaw in crypt_settings.py, where CONFIG_FILE (originally the absolute per-user path ~/.crypt_settings.json) is … Aug 27, 2026
CVE-2026-81696 LOW 3.3 openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape … Aug 27, 2026
CVE-2026-81695 LOW 3.3 openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id containing … Aug 27, 2026
CVE-2026-81694 LOW 3.3 openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing them in the … Aug 27, 2026
CVE-2026-81693 HIGH 7.5 openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply crafted QR images with extremely large … Aug 27, 2026
CVE-2026-81692 HIGH 7.5 openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-bit STREAMINFO total_samples field of FLAC files before using it to size an allocation … Aug 27, 2026
CVE-2026-81691 HIGH 7.5 openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http:// URLs and unconfigured hosts. Attackers on the network … Aug 27, 2026
CVE-2026-81690 HIGH 7.3 openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. The scan enumerated the drive with rglob(), which in … Aug 27, 2026
CVE-2026-81689 HIGH 7.5 openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password, allowing identical keys across all users and … Aug 27, 2026
CVE-2026-81688 HIGH 7.5 openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metadata. Attackers can read this hash without the … Aug 27, 2026
CVE-2026-81687 MEDIUM 5.5 openssl_encrypt versions before 1.4.9 fail to enforce a time ceiling on key derivation function iteration counts specified in file metadata. Attackers can craft files with … Aug 27, 2026
CVE-2026-81686 MEDIUM 6.2 openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set method performs neither a polkit authorization check nor value validation. Any local user … Aug 27, 2026
CVE-2026-81685 LOW 3.3 openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into the irreversible-removal … Aug 27, 2026
CVE-2026-81684 MEDIUM 6.2 In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to the CLI child process on the command line via … Aug 27, 2026
CVE-2026-81683 HIGH 8.4 openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-readable (0644) SharedPreferences file via the desktop … Aug 27, 2026
CVE-2026-81682 MEDIUM 6.2 openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes decrypted plaintext with world-readable default permissions. Attackers can read … Aug 27, 2026
CVE-2026-81681 MEDIUM 4.6 openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB Workspace' with AES-256-GCM encryption and write a marker declaring … Aug 27, 2026
CVE-2026-81680 MEDIUM 4.0 openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can … Aug 27, 2026
CVE-2026-81679 HIGH 7.7 OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST API that allows per-realm tenant administrators to read all tenants' sent … Aug 27, 2026
CVE-2026-81678 HIGH 7.5 AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extract embedded IPv4 addresses from NAT64, 6to4, and Teredo … Aug 27, 2026
CVE-2026-81664 MEDIUM 5.3 The OpenFaaS gateway registers GET /system/telemetry in gateway/main.go and, when basic_auth is enabled, wraps each administrative /system/* handler in auth.DecorateWithBasicAuth. TelemetryHandler was left out of … Aug 27, 2026
CVE-2026-81335 HIGH 7.5 Baserow dispatches an Application Builder data source without acting on the result of its permission check. The dispatch and record-name views in backend/src/baserow/contrib/builder/api/data_sources/views.py are declared … Aug 27, 2026
CVE-2026-81334 MEDIUM 6.1 darknet subscripts its layer array with an index taken from a configuration file without checking it against the array's length. The array is allocated in … Aug 27, 2026