Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45339
Total
3649
Critical
13458
High
13386
Medium
CVE ID Severity Score Description Published
CVE-2026-75913 CRITICAL 9.3 CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed … Aug 18, 2026
CVE-2026-75912 HIGH 7.4 CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by injecting git options into … Aug 18, 2026
CVE-2026-75911 HIGH 7.8 CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by … Aug 18, 2026
CVE-2026-75904 LOW 3.3 libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and … Aug 18, 2026
CVE-2026-75859 HIGH 7.5 CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. … Aug 18, 2026
CVE-2026-75858 HIGH 7.8 CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. The tool's approval_requirement() returns … Aug 18, 2026
CVE-2026-75857 HIGH 7.0 CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Auto. This overrides the default Required … Aug 18, 2026
CVE-2026-75856 HIGH 8.6 CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS responses … Aug 18, 2026
CVE-2026-75485 MEDIUM 5.5 A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, … Aug 18, 2026
CVE-2026-73834 MEDIUM 5.5 A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data … Aug 18, 2026
CVE-2026-73373 UNKNOWN Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML … Aug 18, 2026
CVE-2026-73371 UNKNOWN Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to … Aug 18, 2026
CVE-2026-73337 UNKNOWN Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows to bypass … Aug 18, 2026
CVE-2026-73073 UNKNOWN Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficiently escaped … Aug 18, 2026
CVE-2026-72532 UNKNOWN Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to … Aug 18, 2026
CVE-2026-71574 UNKNOWN Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to … Aug 18, 2026
CVE-2026-71477 MEDIUM 6.7 mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archives record mise/bin/mise with user and group ID 1001 and … Aug 18, 2026
CVE-2026-71365 HIGH 7.7 A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks, AWX extracts the status callback … Aug 18, 2026
CVE-2026-63328 UNKNOWN Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins without confining plugin names to … Aug 18, 2026
CVE-2026-62684 LOW 2.7 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, the Link storage … Aug 18, 2026
CVE-2026-62357 UNKNOWN Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.INITBYDIM and CMS.INITBYPROB accept dimensions whose width times depth times sizeof(int64_t) … Aug 18, 2026
CVE-2026-55839 HIGH 8.7 Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link.ts allows a user with permission to create or update … Aug 18, 2026
CVE-2026-49227 HIGH 7.6 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend comment … Aug 18, 2026
CVE-2026-49226 HIGH 8.3 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post … Aug 18, 2026
CVE-2026-49221 HIGH 8.8 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend digital … Aug 18, 2026