Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44793
Total
3597
Critical
13314
High
13164
Medium
CVE ID Severity Score Description Published
CVE-2026-76156 UNKNOWN OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system … Aug 21, 2026
CVE-2026-76155 UNKNOWN Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the management platform … Aug 21, 2026
CVE-2026-77651 CRITICAL 9.8 The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue … Aug 21, 2026
CVE-2026-77650 CRITICAL 9.8 The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue … Aug 21, 2026
CVE-2026-77649 CRITICAL 9.8 The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue … Aug 21, 2026
CVE-2026-43679 LOW 2.4 This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch … Aug 21, 2026
CVE-2026-20679 MEDIUM 4.3 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. Processing a maliciously crafted … Aug 21, 2026
CVE-2026-16520 UNKNOWN Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, and Genians Genian ZTNA … Aug 21, 2026
CVE-2026-77648 LOW 2.2 In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service … Aug 20, 2026
CVE-2026-77647 CRITICAL 9.8 SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification … Aug 20, 2026
CVE-2026-77113 UNKNOWN Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the … Aug 20, 2026
CVE-2026-77646 UNKNOWN A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of … Aug 20, 2026
CVE-2026-77645 UNKNOWN A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of … Aug 20, 2026
CVE-2026-77644 UNKNOWN A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition. Aug 20, 2026
CVE-2026-77643 MEDIUM 4.4 A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue … Aug 20, 2026
CVE-2026-77642 HIGH 7.5 tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for … Aug 20, 2026
CVE-2026-72860 HIGH 8.5 The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That … Aug 20, 2026
CVE-2026-72858 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 20, 2026
CVE-2026-72848 HIGH 8.6 SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over … Aug 20, 2026
CVE-2026-72846 MEDIUM 6.4 Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/clients/MicrosoftTeams/MicrosoftTeamsClient.ts. In affected versions … Aug 20, 2026
CVE-2026-72843 CRITICAL 9.8 The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the … Aug 20, 2026
CVE-2026-72818 HIGH 7.5 The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisting … Aug 20, 2026
CVE-2026-70105 MEDIUM 6.5 Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. Aug 20, 2026
CVE-2026-69855 HIGH 7.7 Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network. Aug 20, 2026
CVE-2026-69851 CRITICAL 9.9 Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. Aug 20, 2026