Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45656
Total
3653
Critical
13500
High
13451
Medium
CVE ID Severity Score Description Published
CVE-2026-19959 CRITICAL 9.9 A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes … Aug 16, 2026
CVE-2026-19958 MEDIUM 6.3 A security flaw has been discovered in iatsiuk pptr-mcp up to 0.2.7. The impacted element is the function executeCode of the file src/vm-executor.ts of the … Aug 16, 2026
CVE-2026-19957 MEDIUM 6.3 A vulnerability was identified in graphlit graphlit-mcp-server 1.0.1. This affects the function fetch of the file src/tools.ts of the component ssrf-test Endpoint. Such manipulation of … Aug 16, 2026
CVE-2026-19956 MEDIUM 6.3 A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is the function fetch_pagination_url of the file server.py. Such manipulation leads to server-side … Aug 16, 2026
CVE-2026-19955 LOW 3.5 A vulnerability was detected in TrailDB 0.6. Impacted is the function tdb_open of the file /src/tdb.c of the component TOC Validation. The manipulation results in … Aug 16, 2026
CVE-2026-74797 LOW 3.1 OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. … Aug 16, 2026
CVE-2026-74796 MEDIUM 6.1 OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working … Aug 16, 2026
CVE-2026-74795 HIGH 7.5 Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property … Aug 16, 2026
CVE-2026-74794 HIGH 7.5 Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to … Aug 16, 2026
CVE-2026-74792 HIGH 7.5 Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path … Aug 16, 2026
CVE-2026-74791 HIGH 8.6 Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent … Aug 16, 2026
CVE-2026-74790 CRITICAL 9.1 Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can … Aug 16, 2026
CVE-2026-74789 HIGH 7.5 Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and … Aug 16, 2026
CVE-2026-74788 HIGH 7.5 Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on … Aug 16, 2026
CVE-2026-74787 HIGH 7.5 Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates … Aug 16, 2026
CVE-2026-74786 MEDIUM 6.5 Scriban before 7.0.0 (affected versions <= 6.6.0) contains a denial-of-service vulnerability in which the LimitToString safety limit (default 1MB) can be bypassed because ObjectToString resets … Aug 16, 2026
CVE-2026-74785 MEDIUM 6.5 Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass existing safety controls through unbounded string multiplication, uncontrolled BigInteger shift operations, and … Aug 16, 2026
CVE-2026-74784 UNKNOWN Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respecting LoopLimit or LimitToString constraints. Attackers … Aug 16, 2026
CVE-2026-74783 HIGH 7.5 Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates … Aug 16, 2026
CVE-2026-73062 HIGH 7.5 Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic … Aug 16, 2026
CVE-2026-73061 CRITICAL 9.8 Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify … Aug 16, 2026
CVE-2026-73060 HIGH 7.5 Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a … Aug 16, 2026
CVE-2026-73059 MEDIUM 6.5 stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that checks only ViewChannel permission instead of requiring ReadMessageHistory. Attackers with ViewChannel access … Aug 16, 2026
CVE-2026-73058 MEDIUM 5.8 stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass protections via the /proxy … Aug 16, 2026
CVE-2026-73057 HIGH 7.5 stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can … Aug 16, 2026