Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44043
Total
3569
Critical
13212
High
13018
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-76848 | HIGH | 7.5 | TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings and stores it on the expression map without validation. For PostgreSQL-family drivers, createSelectDistinctExpression in src/query-builder/SelectQueryBuilder.ts joins that array … | Aug 24, 2026 |
| CVE-2026-76847 | HIGH | 8.8 | act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4. The control-plane RPCs of that backend, including CreateArtifact, GetSignedArtifactURL, ListArtifacts, FinalizeArtifact … | Aug 24, 2026 |
| CVE-2026-76845 | MEDIUM | 6.5 | adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in util/utils.js enforces containment by comparing only the string form of an archive … | Aug 24, 2026 |
| CVE-2026-76844 | HIGH | 7.4 | webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against a traversal guard and then slicing it at a … | Aug 24, 2026 |
| CVE-2026-76843 | HIGH | 7.8 | The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a … | Aug 24, 2026 |
| CVE-2026-76842 | HIGH | 8.2 | The Mercado Pago Node.js SDK interpolates caller-supplied identifiers into API request paths without percent-encoding them, so characters that are structural in a URL survive into … | Aug 24, 2026 |
| CVE-2026-76841 | HIGH | 8.8 | Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. Six loader call sites … | Aug 24, 2026 |
| CVE-2026-76840 | CRITICAL | 9.6 | RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as … | Aug 24, 2026 |
| CVE-2026-67602 | CRITICAL | 9.1 | phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure … | Aug 24, 2026 |
| CVE-2026-59568 | CRITICAL | 9.1 | Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in … | Aug 24, 2026 |
| CVE-2026-59567 | HIGH | 8.8 | Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a … | Aug 24, 2026 |
| CVE-2026-59566 | HIGH | 8.4 | A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS. | Aug 24, 2026 |
| CVE-2026-59565 | HIGH | 8.8 | A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows. | Aug 24, 2026 |
| CVE-2026-59564 | CRITICAL | 9.1 | An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal. | Aug 24, 2026 |
| CVE-2026-30512 | UNKNOWN | — | A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bachmann entervo HMI prior to V2 R5 P0 M5. … | Aug 24, 2026 |
| CVE-2026-21751 | HIGH | 7.4 | HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized lateral compromise or widespread credential leakage if … | Aug 24, 2026 |
| CVE-2026-17033 | MEDIUM | 6.8 | An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert containing a controlled generatorURL. The attacker is authorized to create the … | Aug 24, 2026 |
| CVE-2025-68833 | MEDIUM | 5.3 | HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources. | Aug 24, 2026 |
| CVE-2026-78365 | UNKNOWN | — | Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify … | Aug 24, 2026 |
| CVE-2026-78247 | HIGH | 7.3 | A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation of … | Aug 24, 2026 |
| CVE-2026-21759 | MEDIUM | 4.3 | HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly. Although no sensitive information (e.g., credentials, PII) was discovered, … | Aug 24, 2026 |
| CVE-2026-21756 | HIGH | 7.2 | HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code … | Aug 24, 2026 |
| CVE-2026-78323 | MEDIUM | 6.5 | A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present … | Aug 24, 2026 |
| CVE-2026-78291 | MEDIUM | 5.3 | Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions. | Aug 24, 2026 |
| CVE-2026-78290 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions. | Aug 24, 2026 |