Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

43999
Total
3569
Critical
13202
High
13005
Medium
CVE ID Severity Score Description Published
CVE-2026-55526 HIGH 8.5 PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_blocked() does not resolve ordinary hostnames before scrape_page fetches them. A hostname such as 127.0.0.1.nip.io … Aug 25, 2026
CVE-2026-16599 UNKNOWN GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used … Aug 25, 2026
CVE-2026-16286 CRITICAL 9.8 Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload … Aug 25, 2026
CVE-2026-15310 UNKNOWN When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion. Aug 25, 2026
CVE-2026-79655 HIGH 7.8 A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or … Aug 25, 2026
CVE-2026-79623 MEDIUM 6.3 A security vulnerability has been detected in FishCodeTech Muteki up to 0.2.5. The affected element is an unknown function of the file .claude/settings.json of the … Aug 25, 2026
CVE-2026-79622 HIGH 7.3 A weakness has been identified in dekdee adobe-xd-mcp 1.0.0. Impacted is an unknown function of the file src/parsers/xd-parser.ts of the component file-access-from-request Endpoint. Executing a … Aug 25, 2026
CVE-2026-55525 HIGH 7.5 PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the web_crawl function validates only the initial URL before _crawl_with_httpx uses httpx.Client(follow_redirects=True). Redirect targets are … Aug 25, 2026
CVE-2026-79406 MEDIUM 4.3 A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function OmsCartItemServiceImpl.updateQuantity of the file /cart/update/quantity. The manipulation of the … Aug 25, 2026
CVE-2026-78887 LOW 3.7 A weakness has been identified in liketrek TREK up to 3.0.22. This impacts the function validateShareTokenForAsset of the component Journey Photo Proxy. Executing a manipulation … Aug 25, 2026
CVE-2026-78886 LOW 3.7 A security flaw has been discovered in liketrek TREK up to 3.0.22. This affects an unknown function of the file server/src/nest/journey/journey-public.controller.ts of the component Public … Aug 25, 2026
CVE-2026-78885 MEDIUM 5.6 A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the function findOrCreateUser of the file server/src/services/oidcService.ts of the component OIDC … Aug 25, 2026
CVE-2026-78581 MEDIUM 4.2 Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain … Aug 25, 2026
CVE-2026-77998 UNKNOWN Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with … Aug 25, 2026
CVE-2026-75803 UNKNOWN Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by … Aug 25, 2026
CVE-2026-63076 HIGH 7.5 Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it … Aug 25, 2026
CVE-2026-63075 HIGH 7.5 Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain … Aug 25, 2026
CVE-2026-63074 MEDIUM 5.9 Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they … Aug 25, 2026
CVE-2026-63073 UNKNOWN Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or … Aug 25, 2026
CVE-2026-63072 HIGH 7.5 Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and … Aug 25, 2026
CVE-2026-57863 HIGH 8.8 Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended … Aug 25, 2026
CVE-2026-54874 HIGH 7.5 Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the … Aug 25, 2026
CVE-2026-18798 HIGH 7.5 Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads … Aug 25, 2026
CVE-2026-14457 HIGH 7.5 Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured … Aug 25, 2026
CVE-2026-79673 MEDIUM 6.5 Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:read scope, a read-only scope, but allows write operations including password changes. An attacker with … Aug 25, 2026