Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44043
Total
3569
Critical
13212
High
13018
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2022-30983 | UNKNOWN | — | A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the … | Aug 24, 2026 |
| CVE-2026-78555 | UNKNOWN | — | RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Although the interface displayed only a shortened representation of each … | Aug 24, 2026 |
| CVE-2026-78553 | UNKNOWN | — | RansomLook created its Flask session-signing key without explicitly restricting the file permissions. The secret_key file was created using the process's default permissions and umask, resulting … | Aug 24, 2026 |
| CVE-2026-78551 | UNKNOWN | — | RansomLook contains multiple weaknesses in its authentication endpoint that allow an unauthenticated remote attacker to enumerate valid usernames, perform unrestricted password-guessing attacks, and potentially exhaust … | Aug 24, 2026 |
| CVE-2026-78430 | MEDIUM | 5.3 | A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall of the file src/tools/handlers.ts of the component Tool Handler. The manipulation of … | Aug 24, 2026 |
| CVE-2026-77923 | MEDIUM | 4.3 | Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the private-project membership check within the clonetasks mass action … | Aug 24, 2026 |
| CVE-2026-77310 | MEDIUM | 5.3 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release … | Aug 24, 2026 |
| CVE-2026-76816 | LOW | 3.5 | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH … | Aug 24, 2026 |
| CVE-2026-76098 | HIGH | 7.5 | Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates … | Aug 24, 2026 |
| CVE-2026-75509 | MEDIUM | 6.5 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership … | Aug 24, 2026 |
| CVE-2026-75369 | UNKNOWN | — | An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via … | Aug 24, 2026 |
| CVE-2026-75368 | UNKNOWN | — | A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying … | Aug 24, 2026 |
| CVE-2026-72714 | MEDIUM | 6.3 | Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module that locally disabled the check is closed. Local … | Aug 24, 2026 |
| CVE-2026-72711 | MEDIUM | 6.3 | The Lean 4 kernel does not check that the body of an opaque declaration is closed. environment::add_opaque omits the check_no_metavar_no_fvar call that the definition and … | Aug 24, 2026 |
| CVE-2026-72705 | MEDIUM | 6.3 | The guard checker in Rocq Prover does not follow recursive calls made through a fixpoint's own arguments. A fixpoint may pass itself as a higher-order … | Aug 24, 2026 |
| CVE-2026-72704 | MEDIUM | 6.3 | The guard checker in Rocq Prover does not recheck the recursive tree representation of an inductive type parameter after that parameter has been changed by … | Aug 24, 2026 |
| CVE-2026-72703 | MEDIUM | 6.3 | The guard checker in Rocq Prover treats a parameter of a nested mutual fixpoint as uniform without examining calls between the different bodies of that … | Aug 24, 2026 |
| CVE-2026-71511 | MEDIUM | 6.5 | Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated attackers with member-read rights to retrieve bcrypt password … | Aug 24, 2026 |
| CVE-2026-71510 | MEDIUM | 6.5 | Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by … | Aug 24, 2026 |
| CVE-2026-63693 | MEDIUM | 6.6 | Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this … | Aug 24, 2026 |
| CVE-2026-61419 | HIGH | 7.8 | Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, … | Aug 24, 2026 |
| CVE-2020-37268 | MEDIUM | 6.3 | Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the caller through Parameter Inline in … | Aug 24, 2026 |
| CVE-2026-78541 | UNKNOWN | — | A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store … | Aug 24, 2026 |
| CVE-2026-78417 | UNKNOWN | — | Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to … | Aug 24, 2026 |
| CVE-2026-75371 | UNKNOWN | — | An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-proximate attackers with UART access to cause a Denial … | Aug 24, 2026 |