Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45339
Total
3649
Critical
13458
High
13386
Medium
CVE ID Severity Score Description Published
CVE-2026-55166 CRITICAL 9.9 Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restriction and trigger AcmeHandler.setup_acme_client … Aug 18, 2026
CVE-2026-55165 MEDIUM 4.8 Lemur manages TLS certificate creation. Prior to 1.9.2, the JWT verifier in lemur/auth/service.py:130-137 used fetch_token_header to read header_data["alg"] from an unverified token and passed that … Aug 18, 2026
CVE-2026-55164 MEDIUM 4.9 Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replacement password directly to users.password, while lemur/users/models.py registered User.hash_password only for the before_insert event. … Aug 18, 2026
CVE-2026-55163 MEDIUM 6.3 Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api/1/roles/ in lemur/roles/views.py:298 authorized updates with RoleMemberPermission(role_id), which allowed either an administrator or any existing member … Aug 18, 2026
CVE-2026-55162 MEDIUM 6.3 Lemur manages TLS certificate creation. Prior to 1.9.2, lemur/certificates/verify.py accepted CRL Distribution Point and OCSP responder URLs from uploaded certificate extensions and used them in … Aug 18, 2026
CVE-2026-47630 MEDIUM 5.5 NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code … Aug 18, 2026
CVE-2026-47629 HIGH 7.5 NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might lead to denial of … Aug 18, 2026
CVE-2026-47628 HIGH 7.5 NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successful exploit might lead … Aug 18, 2026
CVE-2026-47627 CRITICAL 9.8 NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service. Aug 18, 2026
CVE-2026-47606 MEDIUM 6.5 NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code … Aug 18, 2026
CVE-2026-24185 HIGH 7.1 NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, where an administrator could … Aug 18, 2026
CVE-2026-24184 HIGH 7.5 NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where an unauthenticated attacker on an adjacent network could cause … Aug 18, 2026
CVE-2026-24183 HIGH 7.8 NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege management on the system. A successful … Aug 18, 2026
CVE-2026-17106 UNKNOWN The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides … Aug 18, 2026
CVE-2025-9211 MEDIUM 6.7 Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via persistent cross-site … Aug 18, 2026
CVE-2025-9210 HIGH 8.1 Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via tampering with … Aug 18, 2026
CVE-2021-43718 UNKNOWN An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075647YWWV110, which could let a remote malicious user cause a Denial of Service via specially crafted … Aug 18, 2026
CVE-2026-75625 CRITICAL 9.0 Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for … Aug 18, 2026
CVE-2026-75130 CRITICAL 9.0 Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through … Aug 18, 2026
CVE-2026-74046 MEDIUM 4.9 Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() function within cluster.py that allows authenticated cluster peers to exhaust memory by … Aug 18, 2026
CVE-2026-74044 MEDIUM 6.5 Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by supplying a traversal-shaped node name … Aug 18, 2026
CVE-2026-74039 MEDIUM 6.5 Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to exhaust CPU resources by submitting … Aug 18, 2026
CVE-2026-74038 HIGH 7.1 Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrolling an agent with a … Aug 18, 2026
CVE-2026-73502 MEDIUM 5.3 kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.ValidateRequest can encounter a NULL-pointer-dereference denial of service when an operation declares … Aug 18, 2026
CVE-2026-71880 UNKNOWN Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to access server-side files and state … Aug 18, 2026