Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44839
Total
3598
Critical
13323
High
13186
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-63380 | UNKNOWN | — | Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when evws_new_session enters its error path after evhttp_start_ws_ … | Aug 20, 2026 |
| CVE-2026-63379 | UNKNOWN | — | Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in http.c through evhttp_read_trailer and merges them into request … | Aug 20, 2026 |
| CVE-2026-54625 | MEDIUM | 4.8 | django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request … | Aug 20, 2026 |
| CVE-2026-54623 | HIGH | 7.1 | django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the move_plugin endpoint in cms/admin/placeholderadmin.py accepts an attacker-controlled … | Aug 20, 2026 |
| CVE-2026-53425 | UNKNOWN | — | Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never … | Aug 20, 2026 |
| CVE-2026-53424 | UNKNOWN | — | Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it. Samly.Helper.decode_idp_auth_resp/3 … | Aug 20, 2026 |
| CVE-2026-2334 | UNKNOWN | — | An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due … | Aug 20, 2026 |
| CVE-2026-77176 | HIGH | 8.1 | A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of … | Aug 20, 2026 |
| CVE-2026-77025 | MEDIUM | 6.3 | A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentpending.php. This manipulation of the argument … | Aug 20, 2026 |
| CVE-2026-77022 | CRITICAL | 9.9 | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid of the component … | Aug 20, 2026 |
| CVE-2026-77020 | HIGH | 7.3 | A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file password-recovery.php. The manipulation … | Aug 20, 2026 |
| CVE-2026-77019 | HIGH | 7.3 | A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /apartment-visitor/forgotpw.php. Executing a manipulation of the … | Aug 20, 2026 |
| CVE-2026-72845 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 20, 2026 |
| CVE-2026-71492 | UNKNOWN | — | Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py interpolates attacker-controlled Prompt.name and Prompt.version values into a … | Aug 20, 2026 |
| CVE-2026-71428 | CRITICAL | 9.3 | The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 … | Aug 20, 2026 |
| CVE-2026-69183 | HIGH | 7.5 | Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-limit key generator in backend/src/middlewares/rate-limit.ts uses client-controlled cf-connecting-ip and x-forwarded-for headers … | Aug 20, 2026 |
| CVE-2026-65842 | HIGH | 8.2 | Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote image URLs while converting attacker-controlled HTML through htmlToDocxBlob in a … | Aug 20, 2026 |
| CVE-2026-64846 | LOW | 2.8 | Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the recursive-nix experimental feature can exploit … | Aug 20, 2026 |
| CVE-2026-63481 | UNKNOWN | — | Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In version 8.0.1 and earlier, the redirect handling … | Aug 20, 2026 |
| CVE-2026-61704 | HIGH | 7.5 | Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in index.ts validates one resolved IP address but fetches the original hostname, … | Aug 20, 2026 |
| CVE-2026-61625 | MEDIUM | 6.8 | VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.25, 1.136.12, and 1.146.0, vmrestore does not validate backup part path … | Aug 20, 2026 |
| CVE-2026-55642 | CRITICAL | 9.8 | dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/auth.rs passes every protected request to the handler chain when password_hash … | Aug 20, 2026 |
| CVE-2026-55586 | MEDIUM | 6.6 | SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, a crafted CHM file can supply malformed LZX Huffman code lengths to make_decode_table in … | Aug 20, 2026 |
| CVE-2026-55095 | UNKNOWN | — | OpenProject is open-source, web-based project management software. In version 17.5.1 and earlier, an authenticated non-admin project member can request the inplace-edit dialog for a raw … | Aug 20, 2026 |
| CVE-2026-54770 | MEDIUM | 6.1 | WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double … | Aug 20, 2026 |