Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44727
Total
3597
Critical
13286
High
13138
Medium
CVE ID Severity Score Description Published
CVE-2026-78205 MEDIUM 5.8 BentoML's outbound connection safeguard (make_safe_connect in _internal/utils/uri.py) blocks private, loopback, and link-local IP addresses but fails to reject the RFC 6598 shared address space (100.64.0.0/10, … Aug 24, 2026
CVE-2026-78204 MEDIUM 5.4 Ghostwriter through 7.2.6 does not apply per-object authorization on its report template lint endpoints. RoleBasedAccessControlMixin.test_func returns only request.user.is_active unless a view overrides it, and neither … Aug 24, 2026
CVE-2026-78203 HIGH 7.1 Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attackers to attach client-scoped templates from other clients to their … Aug 24, 2026
CVE-2026-78161 HIGH 7.3 A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation … Aug 24, 2026
CVE-2026-78160 MEDIUM 6.3 A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects some unknown processing of the file /user/note.php of the component User … Aug 24, 2026
CVE-2026-78158 MEDIUM 6.3 A flaw has been found in Open5GS 2.8.0. This vulnerability affects unknown code of the component AMF UEContextReleaseRequest Path Handler. Executing a manipulation can lead … Aug 24, 2026
CVE-2026-78157 HIGH 7.4 A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Rx AA-Request Handler. Performing a manipulation … Aug 24, 2026
CVE-2026-78156 HIGH 7.4 A security vulnerability has been detected in Open5GS 2.8.0. Affected by this issue is the function hss_ogs_diam_s6a_air_cb of the file src/hss/hss-s6a-path.c of the component S6a … Aug 24, 2026
CVE-2026-78154 HIGH 7.3 A vulnerability was identified in the-momentum open-wearables up to 0.6.2. This impacts the function redeem_invitation_code of the file backend/app/api/routes/v1/user_invitation_code.py of the component Public Invitation-Code Redemption … Aug 24, 2026
CVE-2026-78148 MEDIUM 5.3 A vulnerability was determined in ggml-org llama.cpp bec4772f6. This affects the function rpc_server::graph_compute of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Executing a manipulation … Aug 24, 2026
CVE-2026-78147 HIGH 7.3 A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing … Aug 23, 2026
CVE-2026-78145 MEDIUM 4.3 A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function _is_safe_url of the file CTFd/utils/validators/__init__.py. Such manipulation of the … Aug 23, 2026
CVE-2026-78144 MEDIUM 6.3 A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /boarders.php of … Aug 23, 2026
CVE-2026-78143 HIGH 7.3 A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file residents.php of the component Resident … Aug 23, 2026
CVE-2026-78142 MEDIUM 6.3 A vulnerability was found in code-projects Barangay Resident Profiling Management System 1.0. This impacts an unknown function of the file /archived_records.php of the component Restore/Delete. … Aug 23, 2026
CVE-2026-78141 HIGH 7.4 A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads … Aug 23, 2026
CVE-2026-78183 UNKNOWN DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the string + 1, which is the size … Aug 23, 2026
CVE-2026-78140 MEDIUM 4.7 A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file src/main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component … Aug 23, 2026
CVE-2026-19565 UNKNOWN Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in CreateSessionAuthKey. CreateSessionAuthKey runs five rounds of SHA-256, … Aug 23, 2026
CVE-2026-75922 UNKNOWN Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream request line. PSGI hands PATH_INFO to … Aug 23, 2026
CVE-2026-9769 HIGH 7.5 justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_selectedcontent(), which recursively … Aug 23, 2026
CVE-2026-8630 MEDIUM 6.1 justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the serialization of raw-text elements such as <style> and <script>. When … Aug 23, 2026
CVE-2026-8445 CRITICAL 9.8 justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown … Aug 23, 2026
CVE-2026-7808 CRITICAL 9.8 justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site … Aug 23, 2026
CVE-2026-77088 MEDIUM 6.1 justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code spans fail to account for blank lines as block boundaries. … Aug 23, 2026