Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44750
Total
3597
Critical
13289
High
13145
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-54681 | MEDIUM | 4.1 | DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, the VisitEmojiAsync method in DiscordChatExporter.Core/Exporting/HtmlMarkdownVisitor.cs interpolates emoji.Name into the alt attribute and emoji.Code into … | Aug 21, 2026 |
| CVE-2026-54134 | UNKNOWN | — | OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, OctoPrint's custom Tornado upload handler and Flask with Werkzeug parse … | Aug 21, 2026 |
| CVE-2026-54073 | UNKNOWN | — | VeraCrypt provides disk encryption with strong security based on TrueCrypt. From 1.26.6 until 1.26.29, file-hosted hidden volume creation forces quick format and the FormatNoFs function … | Aug 21, 2026 |
| CVE-2026-54071 | HIGH | 7.8 | BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/pdfminer/cmapdb.py deserializes untrusted pickle data when CMapDB._load_data() loads CMap files. PDF-controlled … | Aug 21, 2026 |
| CVE-2026-53762 | MEDIUM | 6.2 | VeraCrypt provides disk encryption with strong security based on TrueCrypt. Prior to 1.26.29, non-default builds created with WOLFCRYPT=1 and WOLFCRYPT_BACKEND route SHA-256 and SHA-512 volume-header … | Aug 21, 2026 |
| CVE-2026-35163 | UNKNOWN | — | OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command notification popups use PNotify rendering for printer-controlled payload.command … | Aug 21, 2026 |
| CVE-2026-77237 | MEDIUM | 6.5 | Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with configUSE_QUEUE_SETS=1 to read privileged kernel … | Aug 21, 2026 |
| CVE-2026-77236 | HIGH | 7.3 | Missing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 might allow local users to corrupt secure-world heap metadata via an out-of-bounds write … | Aug 21, 2026 |
| CVE-2026-77235 | HIGH | 7.3 | Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users to cause a use-after-free condition in secure-world memory … | Aug 21, 2026 |
| CVE-2026-77234 | HIGH | 8.8 | Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel context. To remediate this … | Aug 21, 2026 |
| CVE-2026-71862 | HIGH | 7.5 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 … | Aug 21, 2026 |
| CVE-2026-71494 | UNKNOWN | — | Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, internal/hcl/remote_variables_loader.go and related Terraform Cloud, remote-plan, and Terragrunt registry request … | Aug 21, 2026 |
| CVE-2026-71493 | UNKNOWN | — | Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, the readFile, pathExists, isDir, and matchPaths template functions in internal/config/template/parser.go … | Aug 21, 2026 |
| CVE-2026-70656 | MEDIUM | 4.9 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.5.1 … | Aug 21, 2026 |
| CVE-2026-62677 | HIGH | 8.8 | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authenticated user can upload a session-scoped agent bundle … | Aug 21, 2026 |
| CVE-2026-62676 | HIGH | 7.1 | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shared shell-command parser in omnigent/policies/builtins/_shell.py fails to recognize … | Aug 21, 2026 |
| CVE-2026-62675 | HIGH | 8.8 | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated user's agent bundle … | Aug 21, 2026 |
| CVE-2026-62674 | CRITICAL | 9.0 | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but … | Aug 21, 2026 |
| CVE-2026-55241 | HIGH | 7.5 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to … | Aug 21, 2026 |
| CVE-2026-41451 | HIGH | 7.8 | UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_artifact.sh where usernames and home directories … | Aug 21, 2026 |
| CVE-2026-41450 | HIGH | 7.8 | UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_collector function where foreach command output lines are substituted directly … | Aug 21, 2026 |
| CVE-2026-41449 | HIGH | 7.8 | UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_command function that allows attackers to execute arbitrary commands by … | Aug 21, 2026 |
| CVE-2026-27875 | UNKNOWN | — | Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded … | Aug 21, 2026 |
| CVE-2026-17252 | UNKNOWN | — | A stack-based out-of-bounds write vulnerability exists in the login request handling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent … | Aug 21, 2026 |
| CVE-2026-17251 | UNKNOWN | — | A NULL pointer dereference vulnerability exists in the HTTP request parsing functionality of TL-MR6400 v7. An unauthenticated remote attacker can trigger the vulnerability by sending … | Aug 21, 2026 |