Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45339
Total
3649
Critical
13458
High
13386
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-55166 | CRITICAL | 9.9 | Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restriction and trigger AcmeHandler.setup_acme_client … | Aug 18, 2026 |
| CVE-2026-55165 | MEDIUM | 4.8 | Lemur manages TLS certificate creation. Prior to 1.9.2, the JWT verifier in lemur/auth/service.py:130-137 used fetch_token_header to read header_data["alg"] from an unverified token and passed that … | Aug 18, 2026 |
| CVE-2026-55164 | MEDIUM | 4.9 | Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replacement password directly to users.password, while lemur/users/models.py registered User.hash_password only for the before_insert event. … | Aug 18, 2026 |
| CVE-2026-55163 | MEDIUM | 6.3 | Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api/1/roles/ in lemur/roles/views.py:298 authorized updates with RoleMemberPermission(role_id), which allowed either an administrator or any existing member … | Aug 18, 2026 |
| CVE-2026-55162 | MEDIUM | 6.3 | Lemur manages TLS certificate creation. Prior to 1.9.2, lemur/certificates/verify.py accepted CRL Distribution Point and OCSP responder URLs from uploaded certificate extensions and used them in … | Aug 18, 2026 |
| CVE-2026-47630 | MEDIUM | 5.5 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code … | Aug 18, 2026 |
| CVE-2026-47629 | HIGH | 7.5 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of … | Aug 18, 2026 |
| CVE-2026-47628 | HIGH | 7.5 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead … | Aug 18, 2026 |
| CVE-2026-47627 | CRITICAL | 9.8 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service. | Aug 18, 2026 |
| CVE-2026-47606 | MEDIUM | 6.5 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code … | Aug 18, 2026 |
| CVE-2026-24185 | HIGH | 7.1 | NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could … | Aug 18, 2026 |
| CVE-2026-24184 | HIGH | 7.5 | NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where an unauthenticated attacker on an adjacent network could cause … | Aug 18, 2026 |
| CVE-2026-24183 | HIGH | 7.8 | NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege management on the system. A successful … | Aug 18, 2026 |
| CVE-2026-17106 | UNKNOWN | — | The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides … | Aug 18, 2026 |
| CVE-2025-9211 | MEDIUM | 6.7 | Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via persistent cross-site … | Aug 18, 2026 |
| CVE-2025-9210 | HIGH | 8.1 | Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via tampering with … | Aug 18, 2026 |
| CVE-2021-43718 | UNKNOWN | — | An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075647YWWV110, which could let a remote malicious user cause a Denial of Service via specially crafted … | Aug 18, 2026 |
| CVE-2026-75625 | CRITICAL | 9.0 | Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for … | Aug 18, 2026 |
| CVE-2026-75130 | CRITICAL | 9.0 | Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through … | Aug 18, 2026 |
| CVE-2026-74046 | MEDIUM | 4.9 | Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() function within cluster.py that allows authenticated cluster peers to exhaust memory by … | Aug 18, 2026 |
| CVE-2026-74044 | MEDIUM | 6.5 | Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by supplying a traversal-shaped node name … | Aug 18, 2026 |
| CVE-2026-74039 | MEDIUM | 6.5 | Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to exhaust CPU resources by submitting … | Aug 18, 2026 |
| CVE-2026-74038 | HIGH | 7.1 | Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrolling an agent with a … | Aug 18, 2026 |
| CVE-2026-73502 | MEDIUM | 5.3 | kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.ValidateRequest can encounter a NULL-pointer-dereference denial of service when an operation declares … | Aug 18, 2026 |
| CVE-2026-71880 | UNKNOWN | — | Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to access server-side files and state … | Aug 18, 2026 |