Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44710
Total
3597
Critical
13280
High
13130
Medium
CVE ID Severity Score Description Published
CVE-2026-76098 HIGH 7.5 Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates … Aug 24, 2026
CVE-2026-75509 MEDIUM 6.5 joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership … Aug 24, 2026
CVE-2026-75369 UNKNOWN An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via … Aug 24, 2026
CVE-2026-75368 UNKNOWN A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying … Aug 24, 2026
CVE-2026-72714 MEDIUM 6.3 Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module that locally disabled the check is closed. Local … Aug 24, 2026
CVE-2026-72711 MEDIUM 6.3 The Lean 4 kernel does not check that the body of an opaque declaration is closed. environment::add_opaque omits the check_no_metavar_no_fvar call that the definition and … Aug 24, 2026
CVE-2026-72705 MEDIUM 6.3 The guard checker in Rocq Prover does not follow recursive calls made through a fixpoint's own arguments. A fixpoint may pass itself as a higher-order … Aug 24, 2026
CVE-2026-72704 MEDIUM 6.3 The guard checker in Rocq Prover does not recheck the recursive tree representation of an inductive type parameter after that parameter has been changed by … Aug 24, 2026
CVE-2026-72703 MEDIUM 6.3 The guard checker in Rocq Prover treats a parameter of a nested mutual fixpoint as uniform without examining calls between the different bodies of that … Aug 24, 2026
CVE-2026-71511 MEDIUM 6.5 Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated attackers with member-read rights to retrieve bcrypt password … Aug 24, 2026
CVE-2026-71510 MEDIUM 6.5 Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by … Aug 24, 2026
CVE-2026-63693 MEDIUM 6.6 Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this … Aug 24, 2026
CVE-2026-61419 HIGH 7.8 Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, … Aug 24, 2026
CVE-2020-37268 MEDIUM 6.3 Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the caller through Parameter Inline in … Aug 24, 2026
CVE-2026-78541 UNKNOWN A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store … Aug 24, 2026
CVE-2026-78417 UNKNOWN Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to … Aug 24, 2026
CVE-2026-75371 UNKNOWN An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-proximate attackers with UART access to cause a Denial … Aug 24, 2026
CVE-2026-75370 UNKNOWN An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via … Aug 24, 2026
CVE-2026-71832 UNKNOWN Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial … Aug 24, 2026
CVE-2026-71509 MEDIUM 6.5 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint that allows authenticated attackers with expense-creation rights to bypass … Aug 24, 2026
CVE-2026-71508 MEDIUM 6.5 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields … Aug 24, 2026
CVE-2026-71507 MEDIUM 6.5 Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation … Aug 24, 2026
CVE-2026-71506 HIGH 8.1 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete … Aug 24, 2026
CVE-2026-71505 HIGH 7.1 Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation … Aug 24, 2026
CVE-2026-71504 HIGH 8.1 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of … Aug 24, 2026