Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

46113
Total
3679
Critical
13638
High
13568
Medium
CVE ID Severity Score Description Published
CVE-2026-75483 LOW 3.3 powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt segment. Attackers can inject raw escape bytes in the … Aug 17, 2026
CVE-2026-75482 HIGH 7.5 SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without … Aug 17, 2026
CVE-2026-75481 HIGH 8.8 SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate … Aug 17, 2026
CVE-2026-75480 MEDIUM 6.5 OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can … Aug 17, 2026
CVE-2026-75479 HIGH 7.5 JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. … Aug 17, 2026
CVE-2026-75111 HIGH 7.5 Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary files outside the workspace directory. … Aug 17, 2026
CVE-2026-75110 CRITICAL 9.8 MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment variable … Aug 17, 2026
CVE-2026-75109 HIGH 7.1 Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authenticated attackers can disrupt other users' workloads … Aug 17, 2026
CVE-2026-75108 MEDIUM 5.4 Next Terminal fails to enforce per-asset authorization checks on the portal ping and wake-on-LAN endpoints, allowing any authenticated user to probe and wake assets they … Aug 17, 2026
CVE-2026-75106 CRITICAL 9.1 OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers … Aug 17, 2026
CVE-2026-75105 HIGH 7.5 phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/index.php and … Aug 17, 2026
CVE-2026-75104 MEDIUM 5.5 Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply … Aug 17, 2026
CVE-2026-75103 HIGH 8.8 Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate … Aug 17, 2026
CVE-2026-73560 MEDIUM 6.5 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in vllm/transformers_utils/processors/mimo_v2_omni.py passes attacker-controlled image and audio strings through … Aug 17, 2026
CVE-2026-73410 HIGH 8.5 Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outboundFetch.ts pinned a validated address through a Node agent, but the REST integration used getDispatcher from … Aug 17, 2026
CVE-2026-71518 HIGH 7.5 Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent … Aug 17, 2026
CVE-2026-68765 MEDIUM 6.1 hashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePass AESKDF/KDBX v4 module (module 34301) that allows attackers to corrupt … Aug 17, 2026
CVE-2026-67967 CRITICAL 9.8 Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-44867 and CVE-2026-36819 Aug 17, 2026
CVE-2026-67966 CRITICAL 9.8 Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell access. Aug 17, 2026
CVE-2026-67965 CRITICAL 9.8 An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login function Aug 17, 2026
CVE-2026-67926 CRITICAL 9.8 An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module Aug 17, 2026
CVE-2026-67925 MEDIUM 6.1 Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the endpoint /airag/chat/upload Aug 17, 2026
CVE-2026-67917 CRITICAL 9.8 zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` command executes the `db.sql` file extracted … Aug 17, 2026
CVE-2026-66795 CRITICAL 9.1 A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name … Aug 17, 2026
CVE-2026-65976 MEDIUM 6.5 Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.300, a connected peer can send repeated DCLP DataChunk messages to ClipboardChunk::assemble() … Aug 17, 2026