Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41940
Total
3420
Critical
12400
High
12304
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-53720 | UNKNOWN | — | pymonocypher uses cython to wrap the Monocypher C library. Prior to version 4.0.2.8, the argon2i_32 implementation does not check the nb_blocks size. If the caller … | Sep 03, 2026 |
| CVE-2026-50554 | MEDIUM | 5.3 | Note Mark is an open-source note-taking application. Prior to version 0.19.5, GET /api/books/{bookID}/notes is an unauthenticated endpoint that accepts a "deleted" query parameter. When the … | Sep 03, 2026 |
| CVE-2026-48486 | HIGH | 7.5 | Signum Node is a HDD-mined cryptocurrency using an energy efficient and fair Proof-of-Commitment (PoC+) consensus algorithm. Prior to version 3.9.9, an integer overflow in BlockServiceImpl.applyBlock() … | Sep 03, 2026 |
| CVE-2026-85230 | UNKNOWN | — | A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widget URLs were validated only when the widget was rendered and … | Sep 03, 2026 |
| CVE-2026-85227 | UNKNOWN | — | MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in the event attribute filtering query builder. The taggedAttributes and galaxyAttachedAttributes URL parameters were inserted into the … | Sep 03, 2026 |
| CVE-2026-85226 | UNKNOWN | — | MISP contains an authorization flaw in the OnDemand correlation engine where correlations were calculated solely from matching attribute values without applying the distribution, sharing group, … | Sep 03, 2026 |
| CVE-2026-85221 | UNKNOWN | — | MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer property was not explicitly initialized and therefore defaulted to null. When passed to … | Sep 03, 2026 |
| CVE-2026-85216 | UNKNOWN | — | MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate … | Sep 03, 2026 |
| CVE-2026-85214 | HIGH | 8.1 | vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in … | Sep 03, 2026 |
| CVE-2026-85213 | HIGH | 7.6 | Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Authenticated users with minimal account:read permissions can … | Sep 03, 2026 |
| CVE-2026-85212 | HIGH | 8.3 | CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrators and accounts with no roles … | Sep 03, 2026 |
| CVE-2026-85211 | HIGH | 7.7 | Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage … | Sep 03, 2026 |
| CVE-2026-85210 | MEDIUM | 4.3 | Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. Attackers can query the endpoint … | Sep 03, 2026 |
| CVE-2026-85199 | UNKNOWN | — | Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path traversal vulnerability in the REST API. User-controlled identifiers used to create, update, or delete Self-orchestrator … | Sep 03, 2026 |
| CVE-2026-85183 | CRITICAL | 9.3 | Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications. … | Sep 03, 2026 |
| CVE-2026-85182 | HIGH | 7.5 | vhr through commit 03abbd3 fails to verify that the account ID in PUT /hr/pass requests belongs to the authenticated caller. Authenticated attackers can change arbitrary … | Sep 03, 2026 |
| CVE-2026-85181 | CRITICAL | 9.8 | CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can set … | Sep 03, 2026 |
| CVE-2026-85180 | HIGH | 7.5 | Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. An attacker can control a … | Sep 03, 2026 |
| CVE-2026-85179 | HIGH | 8.5 | Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata … | Sep 03, 2026 |
| CVE-2026-85178 | HIGH | 7.7 | Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the vault key's organization identifier. Attackers with admin or owner … | Sep 03, 2026 |
| CVE-2026-85177 | MEDIUM | 5.4 | CRMEB through 6.0.0 fails to validate message ownership in the edit_message handler of MessageSystemController.php, allowing authenticated users to modify arbitrary system inbox messages. Attackers can … | Sep 03, 2026 |
| CVE-2026-85176 | HIGH | 8.8 | DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers can … | Sep 03, 2026 |
| CVE-2026-85135 | MEDIUM | 6.3 | A security flaw has been discovered in ILIAS up to 9.21/10.9/11.2. This affects the function ilObjMediaObjectGUI::uploadMultipleSubtitleFileObject of the file Services/Repository/Service/Resources/ZipAdapter.php of the component MediaPool. The … | Sep 03, 2026 |
| CVE-2026-84989 | HIGH | 7.1 | ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature — `POST /lua/rest/v2/delete/tag/tag.lua` … | Sep 03, 2026 |
| CVE-2026-84971 | MEDIUM | 6.5 | Improper handling of an unexpected value size in the decryption path of a client-side encryption library can cause a failed internal check that terminates the … | Sep 03, 2026 |