Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26101
Total
1954
Critical
7968
High
8216
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-48725 | HIGH | 8.1 | Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp allows terminal output to request access to the local system clipboard. A malicious remote … | Jun 24, 2026 |
| CVE-2026-48721 | HIGH | 8.6 | Warp is an agentic development environment. From 0.2025.10.08.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution permission-check bypass in the default unsandboxed CLI agent profile. The … | Jun 24, 2026 |
| CVE-2026-48720 | HIGH | 8.8 | Warp is an agentic development environment. From 0.2025.03.05.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepts non-inline `OSC 1337;File` payloads from terminal output and materialize the decoded payload as … | Jun 24, 2026 |
| CVE-2026-48719 | HIGH | 8.0 | Warp is an agentic development environment. From 0.2025.08.06.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection in the prompt branch selector. A user who can publish … | Jun 24, 2026 |
| CVE-2026-48704 | HIGH | 8.8 | Warp is an agentic development environment. From 0.2023.10.24.08.03.stable_00 until 0.2026.05.06.15.42.stable_01, Warp may open executable local files through the operating system default file handler. A malicious … | Jun 24, 2026 |
| CVE-2026-48703 | HIGH | 7.8 | Warp is an agentic development environment. From 0.2025.04.09.08.11.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution policy bypass in Agent code search tools. The affected Grep … | Jun 24, 2026 |
| CVE-2026-44022 | MEDIUM | 5.5 | Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.73.0 until 2.91.0, he LaTeX backend's handling of … | Jun 24, 2026 |
| CVE-2026-44020 | HIGH | 7.5 | Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.13.0 until 2.74.0, the USPTO patent XML parser … | Jun 24, 2026 |
| CVE-2026-44017 | HIGH | 7.5 | Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.91.0, the EasyOCR model download functionality extracted … | Jun 24, 2026 |
| CVE-2026-44016 | HIGH | 8.2 | Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. FIn versions >= 2.82.0, < 2.91.0, if the HTML … | Jun 24, 2026 |
| CVE-2026-54906 | UNKNOWN | — | concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock does not verify that the calling thread acquired the write lock. Any thread … | Jun 24, 2026 |
| CVE-2026-54905 | UNKNOWN | — | concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReentrantReadWriteLock can incorrectly grant a write lock after one thread acquires the read lock … | Jun 24, 2026 |
| CVE-2026-54904 | UNKNOWN | — | concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::AtomicReference#update can enter a permanent busy retry loop when the current value is Float::NAN. … | Jun 24, 2026 |
| CVE-2026-54297 | HIGH | 7.5 | Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Faraday::NestedParamsEncoder, the default … | Jun 24, 2026 |
| CVE-2026-53130 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START omfs_fill_super() rejects oversized s_sys_blocksize values (> PAGE_SIZE), but it … | Jun 24, 2026 |
| CVE-2026-53129 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: fs/mbcache: cancel shrink work before destroying the cache mb_cache_destroy() calls shrinker_free() and then frees all … | Jun 24, 2026 |
| CVE-2026-53128 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drbd: Balance RCU calls in drbd_adm_dump_devices() Make drbd_adm_dump_devices() call rcu_read_lock() before rcu_read_unlock() is called. This … | Jun 24, 2026 |
| CVE-2026-53127 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: block: fix zones_cond memory leak on zone revalidation error paths When blk_revalidate_disk_zones() fails after disk_revalidate_zone_resources() … | Jun 24, 2026 |
| CVE-2026-53126 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() Add the missing put_disk() on the error path … | Jun 24, 2026 |
| CVE-2026-53125 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: md: fix array_state=clear sysfs deadlock When "clear" is written to array_state, md_attr_store() breaks sysfs active … | Jun 24, 2026 |
| CVE-2026-53124 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ublk: reset per-IO canceled flag on each fetch If a ublk server starts recovering devices … | Jun 24, 2026 |
| CVE-2026-53123 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: md: wake raid456 reshape waiters before suspend During raid456 reshape, direct IO across the reshape … | Jun 24, 2026 |
| CVE-2026-53122 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit When using the flushoncommit … | Jun 24, 2026 |
| CVE-2026-53121 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: amd-pstate: Fix memory leak in amd_pstate_epp_cpu_init() On failure to set the epp, the function amd_pstate_epp_cpu_init() … | Jun 24, 2026 |
| CVE-2026-53120 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: PCI: use generic driver_override infrastructure When a driver is probed through __driver_attach(), the bus' match() … | Jun 24, 2026 |