Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41940
Total
3420
Critical
12400
High
12304
Medium
CVE ID Severity Score Description Published
CVE-2026-53720 UNKNOWN pymonocypher uses cython to wrap the Monocypher C library. Prior to version 4.0.2.8, the argon2i_32 implementation does not check the nb_blocks size. If the caller … Sep 03, 2026
CVE-2026-50554 MEDIUM 5.3 Note Mark is an open-source note-taking application. Prior to version 0.19.5, GET /api/books/{bookID}/notes is an unauthenticated endpoint that accepts a "deleted" query parameter. When the … Sep 03, 2026
CVE-2026-48486 HIGH 7.5 Signum Node is a HDD-mined cryptocurrency using an energy efficient and fair Proof-of-Commitment (PoC+) consensus algorithm. Prior to version 3.9.9, an integer overflow in BlockServiceImpl.applyBlock() … Sep 03, 2026
CVE-2026-85230 UNKNOWN A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widget URLs were validated only when the widget was rendered and … Sep 03, 2026
CVE-2026-85227 UNKNOWN MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in the event attribute filtering query builder. The taggedAttributes and galaxyAttachedAttributes URL parameters were inserted into the … Sep 03, 2026
CVE-2026-85226 UNKNOWN MISP contains an authorization flaw in the OnDemand correlation engine where correlations were calculated solely from matching attribute values without applying the distribution, sharing group, … Sep 03, 2026
CVE-2026-85221 UNKNOWN MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer property was not explicitly initialized and therefore defaulted to null. When passed to … Sep 03, 2026
CVE-2026-85216 UNKNOWN MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate … Sep 03, 2026
CVE-2026-85214 HIGH 8.1 vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in … Sep 03, 2026
CVE-2026-85213 HIGH 7.6 Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Authenticated users with minimal account:read permissions can … Sep 03, 2026
CVE-2026-85212 HIGH 8.3 CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrators and accounts with no roles … Sep 03, 2026
CVE-2026-85211 HIGH 7.7 Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage … Sep 03, 2026
CVE-2026-85210 MEDIUM 4.3 Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. Attackers can query the endpoint … Sep 03, 2026
CVE-2026-85199 UNKNOWN Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path traversal vulnerability in the REST API. User-controlled identifiers used to create, update, or delete Self-orchestrator … Sep 03, 2026
CVE-2026-85183 CRITICAL 9.3 Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications. … Sep 03, 2026
CVE-2026-85182 HIGH 7.5 vhr through commit 03abbd3 fails to verify that the account ID in PUT /hr/pass requests belongs to the authenticated caller. Authenticated attackers can change arbitrary … Sep 03, 2026
CVE-2026-85181 CRITICAL 9.8 CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can set … Sep 03, 2026
CVE-2026-85180 HIGH 7.5 Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. An attacker can control a … Sep 03, 2026
CVE-2026-85179 HIGH 8.5 Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata … Sep 03, 2026
CVE-2026-85178 HIGH 7.7 Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the vault key's organization identifier. Attackers with admin or owner … Sep 03, 2026
CVE-2026-85177 MEDIUM 5.4 CRMEB through 6.0.0 fails to validate message ownership in the edit_message handler of MessageSystemController.php, allowing authenticated users to modify arbitrary system inbox messages. Attackers can … Sep 03, 2026
CVE-2026-85176 HIGH 8.8 DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers can … Sep 03, 2026
CVE-2026-85135 MEDIUM 6.3 A security flaw has been discovered in ILIAS up to 9.21/10.9/11.2. This affects the function ilObjMediaObjectGUI::uploadMultipleSubtitleFileObject of the file Services/Repository/Service/Resources/ZipAdapter.php of the component MediaPool. The … Sep 03, 2026
CVE-2026-84989 HIGH 7.1 ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature — `POST /lua/rest/v2/delete/tag/tag.lua` … Sep 03, 2026
CVE-2026-84971 MEDIUM 6.5 Improper handling of an unexpected value size in the decryption path of a client-side encryption library can cause a failed internal check that terminates the … Sep 03, 2026