Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43999
Total
3569
Critical
13202
High
13005
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-65081 | HIGH | 8.1 | NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this … | Aug 25, 2026 |
| CVE-2026-55588 | MEDIUM | 6.5 | ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to and including 1.3.2, … | Aug 25, 2026 |
| CVE-2026-53965 | UNKNOWN | — | The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP. In versions 0.5.0 through 0.7.0, the HTTP client transport … | Aug 25, 2026 |
| CVE-2026-52491 | UNKNOWN | — | An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c: main() component | Aug 25, 2026 |
| CVE-2026-52489 | UNKNOWN | — | Buffer Overflow vulnerability in gpac 31becc9e08b88e525a4a62013a4000de1c0f8fd9 allows an attacker to execute arbitrary code via the svgNameToImplementationName() function | Aug 25, 2026 |
| CVE-2026-51368 | UNKNOWN | — | An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter component allows a remote attacker to execute arbitrary code via a crafted … | Aug 25, 2026 |
| CVE-2026-39113 | UNKNOWN | — | Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11) and later snapshots/builds allows an attacker to cause … | Aug 25, 2026 |
| CVE-2026-77585 | MEDIUM | 5.3 | The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may … | Aug 25, 2026 |
| CVE-2026-74932 | HIGH | 7.5 | The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build the URLs of the asset files … | Aug 25, 2026 |
| CVE-2026-68515 | HIGH | 7.1 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through … | Aug 25, 2026 |
| CVE-2026-68514 | MEDIUM | 5.5 | OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 … | Aug 25, 2026 |
| CVE-2026-68513 | HIGH | 7.1 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions 3.3.0 through 3.3.12 and 3.4.0 … | Aug 25, 2026 |
| CVE-2026-66153 | HIGH | 7.0 | The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths. | Aug 25, 2026 |
| CVE-2026-66152 | HIGH | 8.8 | A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Linux client allows an attacker to write arbitrary file as root. | Aug 25, 2026 |
| CVE-2026-65367 | MEDIUM | 5.5 | A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5. … | Aug 25, 2026 |
| CVE-2026-64705 | MEDIUM | 5.5 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7. An app may be able … | Aug 25, 2026 |
| CVE-2026-59981 | HIGH | 7.1 | OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 … | Aug 25, 2026 |
| CVE-2026-55099 | HIGH | 7.5 | icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Component equality method in src/icalendar/cal/component.py compares … | Aug 25, 2026 |
| CVE-2026-45019 | HIGH | 7.2 | Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose … | Aug 25, 2026 |
| CVE-2026-45018 | CRITICAL | 9.8 | Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose … | Aug 25, 2026 |
| CVE-2026-43670 | HIGH | 8.8 | A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, … | Aug 25, 2026 |
| CVE-2026-43657 | LOW | 3.3 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5. A malicious app may be able to … | Aug 25, 2026 |
| CVE-2026-80050 | MEDIUM | 6.5 | ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to multipart upload endpoints, allowing authenticated users to store files with arbitrary extensions. … | Aug 25, 2026 |
| CVE-2026-80049 | HIGH | 8.8 | Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. AuthorizationServerHandler copies recognised identifiers out of the raw JSON … | Aug 25, 2026 |
| CVE-2026-79788 | HIGH | 7.1 | In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required before_action on `defined?(Dradis::Pro)`, a constant that is never defined in CE, so the authorization … | Aug 25, 2026 |