Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41940
Total
3420
Critical
12400
High
12304
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-84185 | MEDIUM | 5.9 | A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the … | Sep 03, 2026 |
| CVE-2026-82521 | MEDIUM | 5.3 | parsedmarc 9.0.6 before 11.0.1 writes forensic report sample files using an output path derived from the email subject. When the subject consists entirely of path … | Sep 03, 2026 |
| CVE-2026-82520 | HIGH | 7.5 | parsedmarc before 11.0.1 decompresses gzip and ZIP attachments in a single unbounded read with no limit on decompressed output size. Because parsedmarc automatically processes incoming … | Sep 03, 2026 |
| CVE-2026-77465 | HIGH | 7.5 | toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0, toml.parse() uses a Peggy 5.1.0 generated recursive-descent parser in lib/parser.js whose peg$parsevalue, … | Sep 03, 2026 |
| CVE-2026-71429 | MEDIUM | 6.2 | stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.5.0, the path filters pick, ignore, … | Sep 03, 2026 |
| CVE-2026-63376 | HIGH | 8.2 | toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as … | Sep 03, 2026 |
| CVE-2026-85207 | LOW | 3.5 | A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.0. Impacted is an unknown function of the file /index.php?q=orderdetails. Such manipulation of the argument … | Sep 03, 2026 |
| CVE-2026-85053 | HIGH | 8.8 | Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted … | Sep 03, 2026 |
| CVE-2026-85052 | LOW | 3.1 | Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory … | Sep 03, 2026 |
| CVE-2026-85051 | HIGH | 8.8 | Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … | Sep 03, 2026 |
| CVE-2026-85050 | CRITICAL | 9.6 | Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the … | Sep 03, 2026 |
| CVE-2026-85049 | HIGH | 8.8 | Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted … | Sep 03, 2026 |
| CVE-2026-85048 | HIGH | 8.3 | Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code … | Sep 03, 2026 |
| CVE-2026-85047 | CRITICAL | 9.6 | Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside … | Sep 03, 2026 |
| CVE-2026-85046 | HIGH | 8.8 | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … | Sep 03, 2026 |
| CVE-2026-85045 | HIGH | 7.5 | Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … | Sep 03, 2026 |
| CVE-2026-85044 | UNKNOWN | — | Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web … | Sep 03, 2026 |
| CVE-2026-85043 | UNKNOWN | — | Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security … | Sep 03, 2026 |
| CVE-2026-85042 | CRITICAL | 9.6 | Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted … | Sep 03, 2026 |
| CVE-2026-82527 | HIGH | 7.5 | R2R through 3.6.6 contains a SQL injection vulnerability that allows unauthenticated attackers to inject SQL predicates into the chunks search query by manipulating the filter … | Sep 03, 2026 |
| CVE-2026-53728 | HIGH | 7.1 | Medplum is a developer platform that enables development of healthcare apps. Prior to version 5.1.6, the external identity provider callback at GET /auth/external accepts attacker-controlled … | Sep 03, 2026 |
| CVE-2026-44506 | HIGH | 8.2 | Medplum is a developer platform that enables development of healthcare apps. In Medplum versions 4.1.10 through 5.1.6, the /oauth2/register endpoint could return the client_secret of … | Sep 03, 2026 |
| CVE-2026-19795 | MEDIUM | 6.2 | IBM Qiskit SDK 2.1.0 through 2.5.1 could allow a local attacker to cause a denial of service due to improper handling of a specially crafted … | Sep 03, 2026 |
| CVE-2026-85396 | HIGH | 7.5 | rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers … | Sep 03, 2026 |
| CVE-2026-85395 | HIGH | 7.1 | UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers … | Sep 03, 2026 |