Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43999
Total
3569
Critical
13202
High
13005
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-55526 | HIGH | 8.5 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_blocked() does not resolve ordinary hostnames before scrape_page fetches them. A hostname such as 127.0.0.1.nip.io … | Aug 25, 2026 |
| CVE-2026-16599 | UNKNOWN | — | GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used … | Aug 25, 2026 |
| CVE-2026-16286 | CRITICAL | 9.8 | Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload … | Aug 25, 2026 |
| CVE-2026-15310 | UNKNOWN | — | When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion. | Aug 25, 2026 |
| CVE-2026-79655 | HIGH | 7.8 | A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or … | Aug 25, 2026 |
| CVE-2026-79623 | MEDIUM | 6.3 | A security vulnerability has been detected in FishCodeTech Muteki up to 0.2.5. The affected element is an unknown function of the file .claude/settings.json of the … | Aug 25, 2026 |
| CVE-2026-79622 | HIGH | 7.3 | A weakness has been identified in dekdee adobe-xd-mcp 1.0.0. Impacted is an unknown function of the file src/parsers/xd-parser.ts of the component file-access-from-request Endpoint. Executing a … | Aug 25, 2026 |
| CVE-2026-55525 | HIGH | 7.5 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the web_crawl function validates only the initial URL before _crawl_with_httpx uses httpx.Client(follow_redirects=True). Redirect targets are … | Aug 25, 2026 |
| CVE-2026-79406 | MEDIUM | 4.3 | A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function OmsCartItemServiceImpl.updateQuantity of the file /cart/update/quantity. The manipulation of the … | Aug 25, 2026 |
| CVE-2026-78887 | LOW | 3.7 | A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of the component Journey Photo Proxy. Executing a manipulation … | Aug 25, 2026 |
| CVE-2026-78886 | LOW | 3.7 | A security flaw has been discovered in liketrek TREK up to 3.0.22. This affects an unknown function of the file server/src/nest/journey/journey-public.controller.ts of the component Public … | Aug 25, 2026 |
| CVE-2026-78885 | MEDIUM | 5.6 | A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the function findOrCreateUser of the file server/src/services/oidcService.ts of the component OIDC … | Aug 25, 2026 |
| CVE-2026-78581 | MEDIUM | 4.2 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain … | Aug 25, 2026 |
| CVE-2026-77998 | UNKNOWN | — | Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with … | Aug 25, 2026 |
| CVE-2026-75803 | UNKNOWN | — | Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by … | Aug 25, 2026 |
| CVE-2026-63076 | HIGH | 7.5 | Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it … | Aug 25, 2026 |
| CVE-2026-63075 | HIGH | 7.5 | Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain … | Aug 25, 2026 |
| CVE-2026-63074 | MEDIUM | 5.9 | Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they … | Aug 25, 2026 |
| CVE-2026-63073 | UNKNOWN | — | Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or … | Aug 25, 2026 |
| CVE-2026-63072 | HIGH | 7.5 | Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and … | Aug 25, 2026 |
| CVE-2026-57863 | HIGH | 8.8 | Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended … | Aug 25, 2026 |
| CVE-2026-54874 | HIGH | 7.5 | Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the … | Aug 25, 2026 |
| CVE-2026-18798 | HIGH | 7.5 | Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads … | Aug 25, 2026 |
| CVE-2026-14457 | HIGH | 7.5 | Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured … | Aug 25, 2026 |
| CVE-2026-79673 | MEDIUM | 6.5 | Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:read scope, a read-only scope, but allows write operations including password changes. An attacker with … | Aug 25, 2026 |