Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44043
Total
3569
Critical
13212
High
13018
Medium
CVE ID Severity Score Description Published
CVE-2026-76848 HIGH 7.5 TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings and stores it on the expression map without validation. For PostgreSQL-family drivers, createSelectDistinctExpression in src/query-builder/SelectQueryBuilder.ts joins that array … Aug 24, 2026
CVE-2026-76847 HIGH 8.8 act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4. The control-plane RPCs of that backend, including CreateArtifact, GetSignedArtifactURL, ListArtifacts, FinalizeArtifact … Aug 24, 2026
CVE-2026-76845 MEDIUM 6.5 adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in util/utils.js enforces containment by comparing only the string form of an archive … Aug 24, 2026
CVE-2026-76844 HIGH 7.4 webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against a traversal guard and then slicing it at a … Aug 24, 2026
CVE-2026-76843 HIGH 7.8 The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a … Aug 24, 2026
CVE-2026-76842 HIGH 8.2 The Mercado Pago Node.js SDK interpolates caller-supplied identifiers into API request paths without percent-encoding them, so characters that are structural in a URL survive into … Aug 24, 2026
CVE-2026-76841 HIGH 8.8 Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. Six loader call sites … Aug 24, 2026
CVE-2026-76840 CRITICAL 9.6 RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as … Aug 24, 2026
CVE-2026-67602 CRITICAL 9.1 phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure … Aug 24, 2026
CVE-2026-59568 CRITICAL 9.1 Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in … Aug 24, 2026
CVE-2026-59567 HIGH 8.8 Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a … Aug 24, 2026
CVE-2026-59566 HIGH 8.4 A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS. Aug 24, 2026
CVE-2026-59565 HIGH 8.8 A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows. Aug 24, 2026
CVE-2026-59564 CRITICAL 9.1 An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal. Aug 24, 2026
CVE-2026-30512 UNKNOWN A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bachmann entervo HMI prior to V2 R5 P0 M5. … Aug 24, 2026
CVE-2026-21751 HIGH 7.4 HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized lateral compromise or widespread credential leakage if … Aug 24, 2026
CVE-2026-17033 MEDIUM 6.8 An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert containing a controlled generatorURL. The attacker is authorized to create the … Aug 24, 2026
CVE-2025-68833 MEDIUM 5.3 HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources. Aug 24, 2026
CVE-2026-78365 UNKNOWN Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify … Aug 24, 2026
CVE-2026-78247 HIGH 7.3 A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation of … Aug 24, 2026
CVE-2026-21759 MEDIUM 4.3 HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly. Although no sensitive information (e.g., credentials, PII) was discovered, … Aug 24, 2026
CVE-2026-21756 HIGH 7.2 HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code … Aug 24, 2026
CVE-2026-78323 MEDIUM 6.5 A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present … Aug 24, 2026
CVE-2026-78291 MEDIUM 5.3 Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions. Aug 24, 2026
CVE-2026-78290 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions. Aug 24, 2026