Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45002
Total
3609
Critical
13358
High
13243
Medium
CVE ID Severity Score Description Published
CVE-2026-76236 UNKNOWN stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism. issue_tombstone defaulted the tenant to "default" instead … Aug 19, 2026
CVE-2026-76234 HIGH 7.5 libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain cryptographic implementation bugs. libcrux-ecdh did not properly check length and clamping during X25519 secret validation … Aug 19, 2026
CVE-2026-76233 MEDIUM 6.7 Renovate versions from 39.53.0 before 40.33.0 contain a command injection vulnerability in the gleam manager where the depName parameter is appended to gleam deps update … Aug 19, 2026
CVE-2026-76232 MEDIUM 6.7 Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv3 manager where the repository parameter is appended to helm registry login … Aug 19, 2026
CVE-2026-76231 MEDIUM 6.7 Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where user-provided dependency names are appended to install and uninstall … Aug 19, 2026
CVE-2026-76230 MEDIUM 6.7 Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm manager where user-provided packageName values are appended to npm install commands … Aug 19, 2026
CVE-2026-76229 MEDIUM 6.7 Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability in the kustomize manager where user-provided chart names are appended to helm pull … Aug 19, 2026
CVE-2026-76228 MEDIUM 6.7 Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) contain a command injection vulnerability in Gradle Wrapper artifact handling. When Renovate processes Gradle … Aug 19, 2026
CVE-2026-76227 MEDIUM 5.5 Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renovate-ce, renovate-ee-server, renovate-ee-worker >=13.3.0 <13.6.0), fail to restrict environment … Aug 19, 2026
CVE-2026-76226 MEDIUM 6.3 Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFileMaintenance. Attackers can execute arbitrary code … Aug 19, 2026
CVE-2026-76225 HIGH 7.7 ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD CSV implementation that fails to validate HTTP/HTTPS URLs. Authenticated attackers can craft … Aug 19, 2026
CVE-2026-76224 HIGH 8.8 ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulnerability in its Gremlin query engine. Although the engine defaults to the documented-secure … Aug 19, 2026
CVE-2026-76223 HIGH 7.1 ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce the UPDATE_SCHEMA permission check when a DEFINE FUNCTION statement targets an already-existing function library. A user … Aug 19, 2026
CVE-2026-76222 HIGH 8.2 GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone … Aug 19, 2026
CVE-2026-76221 HIGH 8.8 GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash … Aug 19, 2026
CVE-2026-76220 HIGH 8.8 GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypassed by combining a single-character kwarg with split_single_char_options=False. Attackers can … Aug 19, 2026
CVE-2026-76219 HIGH 8.1 GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without … Aug 19, 2026
CVE-2026-76218 HIGH 7.5 GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing … Aug 19, 2026
CVE-2026-76217 MEDIUM 6.5 GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and … Aug 19, 2026
CVE-2026-76216 HIGH 7.5 Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals with id N are treated as user principals with users.id == N at three … Aug 19, 2026
CVE-2026-76215 MEDIUM 5.3 phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility checks before returning child resources including comments and attachments. Unauthenticated attackers can retrieve restricted comment text, … Aug 19, 2026
CVE-2026-76214 HIGH 7.4 phpMyFAQ before 4.1.7 (affected versions <= 4.1.5) fails to persist the WebAuthn login challenge generated by prepareForLogin, because neither WebAuthn controller saves the mutated key … Aug 19, 2026
CVE-2026-76213 HIGH 7.4 phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step where the failure counter is session-scoped and reset on each successful password re-authentication. … Aug 19, 2026
CVE-2026-76212 MEDIUM 5.3 phpMyFAQ before 4.1.7, when configured to use PostgreSQL via the native pgsql PHP extension, declares an incorrect LIKE ESCAPE character ('=') in the Search/Database/Pgsql.php backend … Aug 19, 2026
CVE-2026-76211 MEDIUM 4.3 phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT permission on admin API read endpoints for LDAP, Elasticsearch, OpenSearch, and dashboard configuration, allowing any authenticated user … Aug 19, 2026