Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41987
Total
3420
Critical
12405
High
12324
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2021-43613 | MEDIUM | 6.5 | An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User and administrator password hashes are exposed in runtime UEFI variables, leading to escalation of privilege | Sep 03, 2026 |
| CVE-2021-38489 | HIGH | 8.2 | HDD password plaintext is stored in a UEFI variable. | Sep 03, 2026 |
| CVE-2026-84888 | MEDIUM | 4.3 | A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. This vulnerability affects the function shell_exec of the file crates/openfang-runtime/src/tool_runner.rs. This manipulation causes uncontrolled … | Sep 03, 2026 |
| CVE-2026-84887 | MEDIUM | 4.3 | A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affected by this issue is some unknown functionality of the file grounding.py of the component … | Sep 03, 2026 |
| CVE-2026-84886 | MEDIUM | 5.3 | A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affected by this vulnerability is the function ImageData of the file gui_agents/s1/utils/ocr_server.py of the component … | Sep 03, 2026 |
| CVE-2026-84885 | MEDIUM | 4.3 | A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This impacts an unknown function of the file code_agent.py of the component CodeAgent. Such manipulation leads … | Sep 03, 2026 |
| CVE-2026-84851 | HIGH | 7.5 | An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the … | Sep 03, 2026 |
| CVE-2026-84394 | HIGH | 7.5 | fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but … | Sep 03, 2026 |
| CVE-2026-66049 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 03, 2026 |
| CVE-2026-66048 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 03, 2026 |
| CVE-2026-84857 | MEDIUM | 5.3 | A flaw has been found in sigoden aichat up to 0.30.4. This affects an unknown function of the file src/serve.rs of the component API Endpoint. … | Sep 02, 2026 |
| CVE-2026-84856 | MEDIUM | 5.3 | A vulnerability was detected in rowboatlabs rowboat up to 0.9.1. The impacted element is the function request.text/req.json of the file apps/rowboat/app/api/composio/webhook/route.ts of the component Composio … | Sep 02, 2026 |
| CVE-2026-84852 | MEDIUM | 4.4 | A security vulnerability has been detected in Reader Tools PDF Reader App 98.8 on Android. The affected element is the function ActSplashNew.handleDeeplink of the component … | Sep 02, 2026 |
| CVE-2026-84452 | UNKNOWN | — | Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py component … | Sep 02, 2026 |
| CVE-2026-84292 | HIGH | 7.5 | fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port … | Sep 02, 2026 |
| CVE-2026-82524 | HIGH | 7.2 | UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP files through the TinyMCE image upload endpoint due … | Sep 02, 2026 |
| CVE-2026-78662 | HIGH | 7.5 | Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking … | Sep 02, 2026 |
| CVE-2026-75137 | MEDIUM | 6.1 | UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover cleartext vault data from process memory even after … | Sep 02, 2026 |
| CVE-2026-75136 | MEDIUM | 6.1 | UpSignOn for Windows before 7.19.0 contains an insecure credential storage vulnerability that allows local attackers to retrieve the biometric unlock key stored in the Windows … | Sep 02, 2026 |
| CVE-2026-75135 | MEDIUM | 6.1 | UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover the master password and decrypt vault contents by … | Sep 02, 2026 |
| CVE-2026-75134 | MEDIUM | 6.4 | SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive … | Sep 02, 2026 |
| CVE-2026-56855 | HIGH | 7.5 | Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC … | Sep 02, 2026 |
| CVE-2023-20577 | HIGH | 7.4 | A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in … | Sep 02, 2026 |
| CVE-2023-20576 | HIGH | 7.7 | Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation. | Sep 02, 2026 |
| CVE-2026-84841 | HIGH | 7.3 | A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enforcement of server-side … | Sep 02, 2026 |