Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44895
Total
3603
Critical
13333
High
13202
Medium
CVE ID Severity Score Description Published
CVE-2026-76878 UNKNOWN In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for … Aug 19, 2026
CVE-2026-76850 CRITICAL 9.8 LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes with pickle.loads(), … Aug 19, 2026
CVE-2026-76832 HIGH 8.8 Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in … Aug 19, 2026
CVE-2026-76591 HIGH 7.4 A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function log_email_server of the file /cgi-bin/email.cgi of the component ssi. … Aug 19, 2026
CVE-2026-76590 CRITICAL 9.9 A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component … Aug 19, 2026
CVE-2026-76589 CRITICAL 9.9 A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid … Aug 19, 2026
CVE-2026-76405 MEDIUM 4.3 In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" Splunk roles could read a … Aug 19, 2026
CVE-2026-76404 CRITICAL 9.1 In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. … Aug 19, 2026
CVE-2026-76403 HIGH 7.4 In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or alter all relevant data sent from … Aug 19, 2026
CVE-2026-76402 HIGH 8.2 In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure a … Aug 19, 2026
CVE-2026-76401 MEDIUM 5.9 In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure timestamp … Aug 19, 2026
CVE-2026-76400 MEDIUM 5.9 In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API and influence responses … Aug 19, 2026
CVE-2026-76399 HIGH 8.1 In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing … Aug 19, 2026
CVE-2026-76398 MEDIUM 4.3 In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of … Aug 19, 2026
CVE-2026-76397 HIGH 8.1 In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, … Aug 19, 2026
CVE-2026-76396 HIGH 7.5 In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and … Aug 19, 2026
CVE-2026-76395 HIGH 8.8 In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading … Aug 19, 2026
CVE-2026-76394 HIGH 8.3 In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure … Aug 19, 2026
CVE-2026-76393 MEDIUM 5.9 In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by another user by sending a … Aug 19, 2026
CVE-2026-76392 MEDIUM 5.4 In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could obtain predictable or default credentials … Aug 19, 2026
CVE-2026-76391 HIGH 8.3 In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileges, … Aug 19, 2026
CVE-2026-76390 MEDIUM 5.3 In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification through Splunk Web static file … Aug 19, 2026
CVE-2026-76389 HIGH 8.8 In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_talos_enrichment capability could send a crafted … Aug 19, 2026
CVE-2026-76388 HIGH 8.1 In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role could change User and Entity Behavior Analytics (UEBA) … Aug 19, 2026
CVE-2026-76387 HIGH 8.1 In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the mc_investigation_read capability could inject Search Processing … Aug 19, 2026