Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41987
Total
3420
Critical
12405
High
12324
Medium
CVE ID Severity Score Description Published
CVE-2021-43613 MEDIUM 6.5 An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User and administrator password hashes are exposed in runtime UEFI variables, leading to escalation of privilege Sep 03, 2026
CVE-2021-38489 HIGH 8.2 HDD password plaintext is stored in a UEFI variable. Sep 03, 2026
CVE-2026-84888 MEDIUM 4.3 A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. This vulnerability affects the function shell_exec of the file crates/openfang-runtime/src/tool_runner.rs. This manipulation causes uncontrolled … Sep 03, 2026
CVE-2026-84887 MEDIUM 4.3 A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affected by this issue is some unknown functionality of the file grounding.py of the component … Sep 03, 2026
CVE-2026-84886 MEDIUM 5.3 A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affected by this vulnerability is the function ImageData of the file gui_agents/s1/utils/ocr_server.py of the component … Sep 03, 2026
CVE-2026-84885 MEDIUM 4.3 A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This impacts an unknown function of the file code_agent.py of the component CodeAgent. Such manipulation leads … Sep 03, 2026
CVE-2026-84851 HIGH 7.5 An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the … Sep 03, 2026
CVE-2026-84394 HIGH 7.5 fast-uri accepts a host that contains an unbalanced or misplaced authority bracket without reporting an error. A host that starts with an opening bracket but … Sep 03, 2026
CVE-2026-66049 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Sep 03, 2026
CVE-2026-66048 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Sep 03, 2026
CVE-2026-84857 MEDIUM 5.3 A flaw has been found in sigoden aichat up to 0.30.4. This affects an unknown function of the file src/serve.rs of the component API Endpoint. … Sep 02, 2026
CVE-2026-84856 MEDIUM 5.3 A vulnerability was detected in rowboatlabs rowboat up to 0.9.1. The impacted element is the function request.text/req.json of the file apps/rowboat/app/api/composio/webhook/route.ts of the component Composio … Sep 02, 2026
CVE-2026-84852 MEDIUM 4.4 A security vulnerability has been detected in Reader Tools PDF Reader App 98.8 on Android. The affected element is the function ActSplashNew.handleDeeplink of the component … Sep 02, 2026
CVE-2026-84452 UNKNOWN Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py component … Sep 02, 2026
CVE-2026-84292 HIGH 7.5 fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port … Sep 02, 2026
CVE-2026-82524 HIGH 7.2 UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP files through the TinyMCE image upload endpoint due … Sep 02, 2026
CVE-2026-78662 HIGH 7.5 Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking … Sep 02, 2026
CVE-2026-75137 MEDIUM 6.1 UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover cleartext vault data from process memory even after … Sep 02, 2026
CVE-2026-75136 MEDIUM 6.1 UpSignOn for Windows before 7.19.0 contains an insecure credential storage vulnerability that allows local attackers to retrieve the biometric unlock key stored in the Windows … Sep 02, 2026
CVE-2026-75135 MEDIUM 6.1 UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover the master password and decrypt vault contents by … Sep 02, 2026
CVE-2026-75134 MEDIUM 6.4 SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive … Sep 02, 2026
CVE-2026-56855 HIGH 7.5 Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC … Sep 02, 2026
CVE-2023-20577 HIGH 7.4 A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in … Sep 02, 2026
CVE-2023-20576 HIGH 7.7 Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation. Sep 02, 2026
CVE-2026-84841 HIGH 7.3 A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enforcement of server-side … Sep 02, 2026