Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45502
Total
3651
Critical
13471
High
13397
Medium
CVE ID Severity Score Description Published
CVE-2026-64865 UNKNOWN New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update … Aug 17, 2026
CVE-2026-64859 CRITICAL 9.1 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user … Aug 17, 2026
CVE-2026-59829 MEDIUM 4.3 Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1, on sites with category group moderation enabled, the review queue could include … Aug 17, 2026
CVE-2026-55704 MEDIUM 4.3 Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, users who were allowed to view a group’s activity, but were not … Aug 17, 2026
CVE-2026-55674 CRITICAL 9.3 Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id … Aug 17, 2026
CVE-2026-53960 MEDIUM 5.3 Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwise unviewable first-post content was leaked as an excerpt in … Aug 17, 2026
CVE-2026-40144 UNKNOWN A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Windows deployments) prior to version 26.1.2. Insufficient validation of input processed by … Aug 17, 2026
CVE-2025-27772 UNKNOWN UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/new_run` endpoint is vulnerable to remote code … Aug 17, 2026
CVE-2025-27771 UNKNOWN UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/add_prompts` endpoint is vulnerable to remote code … Aug 17, 2026
CVE-2025-27770 UNKNOWN UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/create_project` endpoint is vulnerable to remote code … Aug 17, 2026
CVE-2025-27621 UNKNOWN UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the UpTrain backend creates a new default user … Aug 17, 2026
CVE-2026-73851 UNKNOWN Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed … Aug 17, 2026
CVE-2026-71567 HIGH 7.7 In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables are injected without quoting them either into command lines or … Aug 17, 2026
CVE-2026-71566 CRITICAL 9.3 FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end it's up to the BMC to … Aug 17, 2026
CVE-2026-16049 MEDIUM 4.3 Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify channel permissions when processing API requests with a caller-supplied_ {{post_id}}_, and fails … Aug 17, 2026
CVE-2026-16048 MEDIUM 6.3 Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles which allows a channel … Aug 17, 2026
CVE-2026-16047 MEDIUM 4.3 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate that users have read access to a channel before linking a … Aug 17, 2026
CVE-2026-16046 MEDIUM 4.3 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on write operations for finished playbook runs which allows a run participant … Aug 17, 2026
CVE-2026-16045 MEDIUM 4.3 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth deauthorization and personal access token management endpoints to direct user sessions, which … Aug 17, 2026
CVE-2026-16044 MEDIUM 5.4 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving Board Admin privileges during board archive import which allows a … Aug 17, 2026
CVE-2026-15754 MEDIUM 4.2 Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign endpoint fails to re-validate that each target channel still belongs to the … Aug 17, 2026
CVE-2026-13202 UNKNOWN A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation. This issue affects Opentext Directory Services: through 22.2. Aug 17, 2026
CVE-2026-10527 MEDIUM 6.3 Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile SchemeAdmin flags with a user's current role which allows a user … Aug 17, 2026
CVE-2026-59911 MEDIUM 5.5 Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerability in the svc_tools. A low privileged attacker with local … Aug 17, 2026
CVE-2026-59910 HIGH 7.8 Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged … Aug 17, 2026