Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45002
Total
3609
Critical
13358
High
13243
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-76236 | UNKNOWN | — | stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism. issue_tombstone defaulted the tenant to "default" instead … | Aug 19, 2026 |
| CVE-2026-76234 | HIGH | 7.5 | libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain cryptographic implementation bugs. libcrux-ecdh did not properly check length and clamping during X25519 secret validation … | Aug 19, 2026 |
| CVE-2026-76233 | MEDIUM | 6.7 | Renovate versions from 39.53.0 before 40.33.0 contain a command injection vulnerability in the gleam manager where the depName parameter is appended to gleam deps update … | Aug 19, 2026 |
| CVE-2026-76232 | MEDIUM | 6.7 | Renovate versions from 31.51.0 before 40.33.0 contain a command injection vulnerability in the helmv3 manager where the repository parameter is appended to helm registry login … | Aug 19, 2026 |
| CVE-2026-76231 | MEDIUM | 6.7 | Renovate versions from 32.135.0 before 40.33.0 contain a command injection vulnerability in the hermit manager where user-provided dependency names are appended to install and uninstall … | Aug 19, 2026 |
| CVE-2026-76230 | MEDIUM | 6.7 | Renovate versions from 35.63.0 before 40.33.0 contain a command injection vulnerability in the npm manager where user-provided packageName values are appended to npm install commands … | Aug 19, 2026 |
| CVE-2026-76229 | MEDIUM | 6.7 | Renovate versions from 39.218.0 before 40.33.0 contain an arbitrary command injection vulnerability in the kustomize manager where user-provided chart names are appended to helm pull … | Aug 19, 2026 |
| CVE-2026-76228 | MEDIUM | 6.7 | Renovate versions >=32.124.0 and before 42.68.5 (and Mend renovate-ce/renovate-ee before 13.3.0) contain a command injection vulnerability in Gradle Wrapper artifact handling. When Renovate processes Gradle … | Aug 19, 2026 |
| CVE-2026-76227 | MEDIUM | 5.5 | Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renovate-ce, renovate-ee-server, renovate-ee-worker >=13.3.0 <13.6.0), fail to restrict environment … | Aug 19, 2026 |
| CVE-2026-76226 | MEDIUM | 6.3 | Renovate versions from 43.65.0 before 43.102.11 contain a remote code execution vulnerability in bazel-module and bazelisk managers when using lockFileMaintenance. Attackers can execute arbitrary code … | Aug 19, 2026 |
| CVE-2026-76225 | HIGH | 7.7 | ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD CSV implementation that fails to validate HTTP/HTTPS URLs. Authenticated attackers can craft … | Aug 19, 2026 |
| CVE-2026-76224 | HIGH | 8.8 | ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulnerability in its Gremlin query engine. Although the engine defaults to the documented-secure … | Aug 19, 2026 |
| CVE-2026-76223 | HIGH | 7.1 | ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce the UPDATE_SCHEMA permission check when a DEFINE FUNCTION statement targets an already-existing function library. A user … | Aug 19, 2026 |
| CVE-2026-76222 | HIGH | 8.2 | GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone … | Aug 19, 2026 |
| CVE-2026-76221 | HIGH | 8.8 | GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash … | Aug 19, 2026 |
| CVE-2026-76220 | HIGH | 8.8 | GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypassed by combining a single-character kwarg with split_single_char_options=False. Attackers can … | Aug 19, 2026 |
| CVE-2026-76219 | HIGH | 8.1 | GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without … | Aug 19, 2026 |
| CVE-2026-76218 | HIGH | 7.5 | GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing … | Aug 19, 2026 |
| CVE-2026-76217 | MEDIUM | 6.5 | GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and … | Aug 19, 2026 |
| CVE-2026-76216 | HIGH | 7.5 | Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals with id N are treated as user principals with users.id == N at three … | Aug 19, 2026 |
| CVE-2026-76215 | MEDIUM | 5.3 | phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility checks before returning child resources including comments and attachments. Unauthenticated attackers can retrieve restricted comment text, … | Aug 19, 2026 |
| CVE-2026-76214 | HIGH | 7.4 | phpMyFAQ before 4.1.7 (affected versions <= 4.1.5) fails to persist the WebAuthn login challenge generated by prepareForLogin, because neither WebAuthn controller saves the mutated key … | Aug 19, 2026 |
| CVE-2026-76213 | HIGH | 7.4 | phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step where the failure counter is session-scoped and reset on each successful password re-authentication. … | Aug 19, 2026 |
| CVE-2026-76212 | MEDIUM | 5.3 | phpMyFAQ before 4.1.7, when configured to use PostgreSQL via the native pgsql PHP extension, declares an incorrect LIKE ESCAPE character ('=') in the Search/Database/Pgsql.php backend … | Aug 19, 2026 |
| CVE-2026-76211 | MEDIUM | 4.3 | phpMyFAQ before 4.1.7 fails to properly enforce CONFIGURATION_EDIT permission on admin API read endpoints for LDAP, Elasticsearch, OpenSearch, and dashboard configuration, allowing any authenticated user … | Aug 19, 2026 |