Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45502
Total
3651
Critical
13471
High
13397
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-75104 | MEDIUM | 5.5 | Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply … | Aug 17, 2026 |
| CVE-2026-75103 | HIGH | 8.8 | Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate … | Aug 17, 2026 |
| CVE-2026-73560 | MEDIUM | 6.5 | vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in vllm/transformers_utils/processors/mimo_v2_omni.py passes attacker-controlled image and audio strings through … | Aug 17, 2026 |
| CVE-2026-73410 | HIGH | 8.5 | Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outboundFetch.ts pinned a validated address through a Node agent, but the REST integration used getDispatcher from … | Aug 17, 2026 |
| CVE-2026-71518 | HIGH | 7.5 | Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent … | Aug 17, 2026 |
| CVE-2026-68765 | MEDIUM | 6.1 | hashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePass AESKDF/KDBX v4 module (module 34301) that allows attackers to corrupt … | Aug 17, 2026 |
| CVE-2026-67967 | CRITICAL | 9.8 | Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-44867 and CVE-2026-36819 | Aug 17, 2026 |
| CVE-2026-67966 | CRITICAL | 9.8 | Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell access. | Aug 17, 2026 |
| CVE-2026-67965 | CRITICAL | 9.8 | An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login function | Aug 17, 2026 |
| CVE-2026-67926 | CRITICAL | 9.8 | An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module | Aug 17, 2026 |
| CVE-2026-67925 | MEDIUM | 6.1 | Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the endpoint /airag/chat/upload | Aug 17, 2026 |
| CVE-2026-67917 | CRITICAL | 9.8 | zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` command executes the `db.sql` file extracted … | Aug 17, 2026 |
| CVE-2026-66795 | CRITICAL | 9.1 | A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name … | Aug 17, 2026 |
| CVE-2026-65976 | MEDIUM | 6.5 | Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.300, a connected peer can send repeated DCLP DataChunk messages to ClipboardChunk::assemble() … | Aug 17, 2026 |
| CVE-2026-65974 | CRITICAL | 9.9 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in … | Aug 17, 2026 |
| CVE-2026-65832 | HIGH | 8.2 | Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthenticated Deskflow server can send kMsgDSetOptions (DSOP) values to ServerProxy::setOptions() … | Aug 17, 2026 |
| CVE-2026-65822 | HIGH | 7.6 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/report/inactive_customers/inactive_customers.py accepts an unvalidated doctype filter and interpolates it … | Aug 17, 2026 |
| CVE-2026-65640 | HIGH | 8.8 | WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and … | Aug 17, 2026 |
| CVE-2026-64657 | HIGH | 8.4 | Budibase is an open-source low-code platform. Prior to 3.39.19, the PostgreSQL datasource connector in packages/server/src/integrations/postgres.ts interpolates the user-controlled schema configuration field into a SET search_path … | Aug 17, 2026 |
| CVE-2026-63409 | HIGH | 8.2 | Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malicious Deskflow server can send an odd-length DSOP vector to … | Aug 17, 2026 |
| CVE-2026-54356 | HIGH | 7.1 | Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts and packages/server/src/api/controllers/static/index.ts allows an authenticated published-app user with the BASIC role to … | Aug 17, 2026 |
| CVE-2026-54336 | MEDIUM | 5.4 | JumpServer is an open source bastion host and an operation and maintenance security audit system. From 4.8.0 until 4.10.17, an authenticated user with SFTP permission … | Aug 17, 2026 |
| CVE-2026-47698 | CRITICAL | 9.8 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype … | Aug 17, 2026 |
| CVE-2026-47686 | CRITICAL | 9.9 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and AggregateError.errors but does not sanitize Error.cause, allowing … | Aug 17, 2026 |
| CVE-2026-47683 | UNKNOWN | — | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js does not cover Buffer.concat(list, totalLength) or Buffer.from(arrayLike) with an … | Aug 17, 2026 |