Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43999
Total
3569
Critical
13202
High
13005
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-79787 | CRITICAL | 9.8 | Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can … | Aug 25, 2026 |
| CVE-2026-79786 | HIGH | 7.1 | Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI without validation, allowing attackers to register clients pointing to attacker-controlled hosts. … | Aug 25, 2026 |
| CVE-2026-78379 | HIGH | 8.1 | Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute … | Aug 25, 2026 |
| CVE-2026-65979 | UNKNOWN | — | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.12, the … | Aug 25, 2026 |
| CVE-2026-62986 | MEDIUM | 4.3 | OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 … | Aug 25, 2026 |
| CVE-2026-61555 | MEDIUM | 5.5 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through … | Aug 25, 2026 |
| CVE-2026-59985 | MEDIUM | 5.5 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.2.0 through 3.2.10, 3.3.0 … | Aug 25, 2026 |
| CVE-2026-55663 | MEDIUM | 5.6 | mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, … | Aug 25, 2026 |
| CVE-2026-55620 | HIGH | 7.5 | eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to … | Aug 25, 2026 |
| CVE-2026-55619 | MEDIUM | 5.3 | eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to … | Aug 25, 2026 |
| CVE-2026-55618 | MEDIUM | 6.5 | eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to … | Aug 25, 2026 |
| CVE-2026-55609 | HIGH | 7.1 | sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear time. Prior to consciousness-explorer 1.1.2 and sublinear-time-solver 1.6.0, the export_state … | Aug 25, 2026 |
| CVE-2026-80051 | UNKNOWN | — | github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar variable value matches its declared type. The built-in coerceString and coerceBool functions (scalars.go) … | Aug 25, 2026 |
| CVE-2026-79992 | HIGH | 7.8 | A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login … | Aug 25, 2026 |
| CVE-2026-76198 | MEDIUM | 5.5 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability … | Aug 25, 2026 |
| CVE-2026-76197 | CRITICAL | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result … | Aug 25, 2026 |
| CVE-2026-76195 | CRITICAL | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result … | Aug 25, 2026 |
| CVE-2026-76193 | CRITICAL | 10.0 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the … | Aug 25, 2026 |
| CVE-2026-76189 | MEDIUM | 6.2 | CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this … | Aug 25, 2026 |
| CVE-2026-75770 | HIGH | 7.8 | Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation … | Aug 25, 2026 |
| CVE-2026-75769 | HIGH | 7.8 | Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. … | Aug 25, 2026 |
| CVE-2026-75768 | HIGH | 7.8 | Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. … | Aug 25, 2026 |
| CVE-2026-75767 | HIGH | 7.8 | Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. … | Aug 25, 2026 |
| CVE-2026-75766 | HIGH | 7.8 | Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. … | Aug 25, 2026 |
| CVE-2026-75752 | MEDIUM | 5.5 | Substance3D - Painter is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to … | Aug 25, 2026 |