Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44710
Total
3597
Critical
13280
High
13130
Medium
CVE ID Severity Score Description Published
CVE-2026-39915 HIGH 8.1 TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to inject arbitrary HTTP headers and response body content by embedding unsanitized … Aug 24, 2026
CVE-2026-39914 MEDIUM 6.5 TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arbitrary SQL queries to a privileged dashboard Excel export … Aug 24, 2026
CVE-2026-21755 MEDIUM 5.3 HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or credential stuffing attacks, or cause a … Aug 24, 2026
CVE-2026-19874 CRITICAL 9.1 A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The … Aug 24, 2026
CVE-2026-78386 UNKNOWN RansomLook exposed sensitive operator-side scraping configuration through multiple unauthenticated API responses. Location records associated with ransomware groups and markets were returned largely verbatim to unauthenticated … Aug 24, 2026
CVE-2026-78385 UNKNOWN RansomLook contains insufficient resource validation in the analysis PDF generation functionality. Analysis documents are converted from Markdown to HTML and passed to WeasyPrint for PDF … Aug 24, 2026
CVE-2026-78381 UNKNOWN RansomLook contains a path traversal vulnerability in the handling of the screen field associated with group posts. The GroupPost.get API handler concatenates the database-controlled screen … Aug 24, 2026
CVE-2026-78380 UNKNOWN RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim posts to external notification channels. The post-processing logic … Aug 24, 2026
CVE-2026-78378 UNKNOWN Ransomlook contains a Redis glob pattern injection vulnerability caused by insufficient neutralization of user-controlled input before it is incorporated into Redis SCAN MATCH patterns. The … Aug 24, 2026
CVE-2026-78376 HIGH 8.8 A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption. Aug 24, 2026
CVE-2026-78372 UNKNOWN RansomLook does not consistently enforce authorization checks when accessing groups, markets, and ransom notes marked as private. An unauthenticated or otherwise unauthorized remote attacker can … Aug 24, 2026
CVE-2026-78370 UNKNOWN RansomLook contains an authorization flaw in its legacy database export functionality that can allow unauthenticated remote users to retrieve information intended to remain private. The … Aug 24, 2026
CVE-2026-78369 UNKNOWN RansomLook contains a missing authentication vulnerability in the /admin/crypto/group/new endpoint. While the endpoint provides an administrative function for creating new crypto group entries, it was … Aug 24, 2026
CVE-2026-78367 HIGH 7.0 A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive … Aug 24, 2026
CVE-2026-78250 MEDIUM 4.3 A vulnerability was identified in bytebot-ai bytebot 0.0.1. The affected element is an unknown function of the component Agent Execution Workflow. Such manipulation leads to … Aug 24, 2026
CVE-2026-78248 HIGH 7.3 A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/ajax.php?action=save_settings. This manipulation of the … Aug 24, 2026
CVE-2026-77995 UNKNOWN Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of a cookie value allows actors to login … Aug 24, 2026
CVE-2026-76848 HIGH 7.5 TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings and stores it on the expression map without validation. For PostgreSQL-family drivers, createSelectDistinctExpression in src/query-builder/SelectQueryBuilder.ts joins that array … Aug 24, 2026
CVE-2026-76847 HIGH 8.8 act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4. The control-plane RPCs of that backend, including CreateArtifact, GetSignedArtifactURL, ListArtifacts, FinalizeArtifact … Aug 24, 2026
CVE-2026-76845 MEDIUM 6.5 adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in util/utils.js enforces containment by comparing only the string form of an archive … Aug 24, 2026
CVE-2026-76844 HIGH 7.4 webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against a traversal guard and then slicing it at a … Aug 24, 2026
CVE-2026-76843 HIGH 7.8 The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a … Aug 24, 2026
CVE-2026-76842 HIGH 8.2 The Mercado Pago Node.js SDK interpolates caller-supplied identifiers into API request paths without percent-encoding them, so characters that are structural in a URL survive into … Aug 24, 2026
CVE-2026-76841 HIGH 8.8 Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. Six loader call sites … Aug 24, 2026
CVE-2026-76840 CRITICAL 9.6 RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as … Aug 24, 2026