Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44710
Total
3597
Critical
13280
High
13130
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-39915 | HIGH | 8.1 | TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to inject arbitrary HTTP headers and response body content by embedding unsanitized … | Aug 24, 2026 |
| CVE-2026-39914 | MEDIUM | 6.5 | TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arbitrary SQL queries to a privileged dashboard Excel export … | Aug 24, 2026 |
| CVE-2026-21755 | MEDIUM | 5.3 | HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or credential stuffing attacks, or cause a … | Aug 24, 2026 |
| CVE-2026-19874 | CRITICAL | 9.1 | A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The … | Aug 24, 2026 |
| CVE-2026-78386 | UNKNOWN | — | RansomLook exposed sensitive operator-side scraping configuration through multiple unauthenticated API responses. Location records associated with ransomware groups and markets were returned largely verbatim to unauthenticated … | Aug 24, 2026 |
| CVE-2026-78385 | UNKNOWN | — | RansomLook contains insufficient resource validation in the analysis PDF generation functionality. Analysis documents are converted from Markdown to HTML and passed to WeasyPrint for PDF … | Aug 24, 2026 |
| CVE-2026-78381 | UNKNOWN | — | RansomLook contains a path traversal vulnerability in the handling of the screen field associated with group posts. The GroupPost.get API handler concatenates the database-controlled screen … | Aug 24, 2026 |
| CVE-2026-78380 | UNKNOWN | — | RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim posts to external notification channels. The post-processing logic … | Aug 24, 2026 |
| CVE-2026-78378 | UNKNOWN | — | Ransomlook contains a Redis glob pattern injection vulnerability caused by insufficient neutralization of user-controlled input before it is incorporated into Redis SCAN MATCH patterns. The … | Aug 24, 2026 |
| CVE-2026-78376 | HIGH | 8.8 | A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption. | Aug 24, 2026 |
| CVE-2026-78372 | UNKNOWN | — | RansomLook does not consistently enforce authorization checks when accessing groups, markets, and ransom notes marked as private. An unauthenticated or otherwise unauthorized remote attacker can … | Aug 24, 2026 |
| CVE-2026-78370 | UNKNOWN | — | RansomLook contains an authorization flaw in its legacy database export functionality that can allow unauthenticated remote users to retrieve information intended to remain private. The … | Aug 24, 2026 |
| CVE-2026-78369 | UNKNOWN | — | RansomLook contains a missing authentication vulnerability in the /admin/crypto/group/new endpoint. While the endpoint provides an administrative function for creating new crypto group entries, it was … | Aug 24, 2026 |
| CVE-2026-78367 | HIGH | 7.0 | A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive … | Aug 24, 2026 |
| CVE-2026-78250 | MEDIUM | 4.3 | A vulnerability was identified in bytebot-ai bytebot 0.0.1. The affected element is an unknown function of the component Agent Execution Workflow. Such manipulation leads to … | Aug 24, 2026 |
| CVE-2026-78248 | HIGH | 7.3 | A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/ajax.php?action=save_settings. This manipulation of the … | Aug 24, 2026 |
| CVE-2026-77995 | UNKNOWN | — | Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login … | Aug 24, 2026 |
| CVE-2026-76848 | HIGH | 7.5 | TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings and stores it on the expression map without validation. For PostgreSQL-family drivers, createSelectDistinctExpression in src/query-builder/SelectQueryBuilder.ts joins that array … | Aug 24, 2026 |
| CVE-2026-76847 | HIGH | 8.8 | act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4. The control-plane RPCs of that backend, including CreateArtifact, GetSignedArtifactURL, ListArtifacts, FinalizeArtifact … | Aug 24, 2026 |
| CVE-2026-76845 | MEDIUM | 6.5 | adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in util/utils.js enforces containment by comparing only the string form of an archive … | Aug 24, 2026 |
| CVE-2026-76844 | HIGH | 7.4 | webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against a traversal guard and then slicing it at a … | Aug 24, 2026 |
| CVE-2026-76843 | HIGH | 7.8 | The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a … | Aug 24, 2026 |
| CVE-2026-76842 | HIGH | 8.2 | The Mercado Pago Node.js SDK interpolates caller-supplied identifiers into API request paths without percent-encoding them, so characters that are structural in a URL survive into … | Aug 24, 2026 |
| CVE-2026-76841 | HIGH | 8.8 | Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. Six loader call sites … | Aug 24, 2026 |
| CVE-2026-76840 | CRITICAL | 9.6 | RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as … | Aug 24, 2026 |