Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44750
Total
3597
Critical
13289
High
13145
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-69228 | MEDIUM | 5.3 | There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a … | Aug 21, 2026 |
| CVE-2026-69225 | MEDIUM | 5.9 | There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenticated attacker to … | Aug 21, 2026 |
| CVE-2026-69224 | MEDIUM | 5.9 | There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstances allow a remote, … | Aug 21, 2026 |
| CVE-2026-68508 | HIGH | 7.8 | Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.4, hydra.utils.instantiate() resolves and calls Python objects selected by configuration through _resolve_target() in hydra/_internal/instantiate/_instantiate2.py, … | Aug 21, 2026 |
| CVE-2026-67619 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 21, 2026 |
| CVE-2026-64679 | HIGH | 8.1 | Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not consistently validate user-controlled … | Aug 21, 2026 |
| CVE-2026-63421 | HIGH | 7.5 | Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core/queries/resolvers.ts compares the signed take argument directly with graphql.maxTake, allowing … | Aug 21, 2026 |
| CVE-2026-63135 | HIGH | 8.2 | YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS stores the HTTP Referer header through yourls_get_referrer(), yourls_sanitize_url_safe(), and yourls_log_redirect(), … | Aug 21, 2026 |
| CVE-2026-62316 | HIGH | 8.8 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does … | Aug 21, 2026 |
| CVE-2026-62283 | CRITICAL | 9.9 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind … | Aug 21, 2026 |
| CVE-2026-61824 | HIGH | 8.2 | Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:image values, and video descriptions into HTML strings … | Aug 21, 2026 |
| CVE-2026-61539 | CRITICAL | 10.0 | Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in … | Aug 21, 2026 |
| CVE-2026-59989 | UNKNOWN | — | Phalcon is a high-performance, full-stack PHP framework. In 5.15.0 and earlier, resolveFilter in phalcon/Mvc/View/Engine/Volt/Compiler.zep builds the join filter by inserting the raw separator and array … | Aug 21, 2026 |
| CVE-2026-55185 | UNKNOWN | — | Miniflux 2 is an open source feed reader. Prior to 2.3.1, IsRelativePath in internal/urllib/url.go accepts redirect targets containing backslashes because Go URL parsing treats them … | Aug 21, 2026 |
| CVE-2026-55168 | MEDIUM | 6.5 | Runtipi is a personal homeserver orchestrator. In 4.10.0 and earlier, Runtipi accepts symbolic links from an attacker-controlled backup archive and copies them into live application … | Aug 21, 2026 |
| CVE-2026-54457 | HIGH | 7.7 | TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts … | Aug 21, 2026 |
| CVE-2026-53656 | MEDIUM | 6.3 | FiftyOne is an open-source platform for refining high-quality datasets and visual AI models. Prior to 1.17.0, the FiftyOne App/API server in fiftyone/server/app.py and the /media … | Aug 21, 2026 |
| CVE-2026-53572 | MEDIUM | 5.9 | KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgresql_scaler.go constructs libpq-style connection strings from tenant-controlled host, port, userName, dbName, sslmode, and password … | Aug 21, 2026 |
| CVE-2026-50538 | HIGH | 8.8 | LibVNCClient is a library for easy implementation of a VNC client. In versions 0.9.12 through 0.9.15, a malicious (or man-in-the-middle) VNC server can force a … | Aug 21, 2026 |
| CVE-2026-45271 | MEDIUM | 5.5 | Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. Picotls implements its own ASN.1 validation helper, … | Aug 21, 2026 |
| CVE-2026-45099 | UNKNOWN | — | Terragrunt is a flexible orchestration tool that allows Infrastructure as Code written in OpenTofu or Terraform to scale. Prior to 1.0.4, Terragrunt trusts paths decoded … | Aug 21, 2026 |
| CVE-2026-44517 | MEDIUM | 6.3 | Buildah is a tool that facilitates building OCI images. From 1.38.1 until 1.43.2 and 1.44.0, TempDirForURL in define/types.go does not securely confine Git repository subdirectories … | Aug 21, 2026 |
| CVE-2026-31880 | HIGH | 8.0 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universal search. … | Aug 21, 2026 |
| CVE-2026-31803 | HIGH | 8.0 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in pages/tagadmin.php. This … | Aug 21, 2026 |
| CVE-2026-30890 | HIGH | 8.0 | Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the synchro import … | Aug 21, 2026 |