Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
46113
Total
3679
Critical
13638
High
13568
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-74887 | NONE | — | openssl_encrypt before 1.4.0 imports Python's non-cryptographic 'random' module (Mersenne Twister PRNG) at line 15 of openssl_encrypt/modules/pqc.py. No direct calls to random.* were present in the … | Aug 17, 2026 |
| CVE-2026-74886 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. … | Aug 17, 2026 |
| CVE-2026-74885 | LOW | 3.6 | openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero restored modules and corrupting audit trails. … | Aug 17, 2026 |
| CVE-2026-74884 | HIGH | 7.5 | openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugin_id parameter is not sanitized before constructing the plugin config … | Aug 17, 2026 |
| CVE-2026-74883 | HIGH | 8.8 | openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers … | Aug 17, 2026 |
| CVE-2026-74882 | HIGH | 7.5 | openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityProxyConfig trusted_proxies. Attackers on private networks … | Aug 17, 2026 |
| CVE-2026-74881 | MEDIUM | 6.5 | openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create malicious websites that make authenticated cross-origin … | Aug 17, 2026 |
| CVE-2026-74880 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy … | Aug 17, 2026 |
| CVE-2026-74879 | HIGH | 7.5 | openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger … | Aug 17, 2026 |
| CVE-2026-74878 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. … | Aug 17, 2026 |
| CVE-2026-74877 | HIGH | 8.8 | openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clients to revoke any other client's key. Attackers … | Aug 17, 2026 |
| CVE-2026-74876 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. Attackers can call from_dict() followed by … | Aug 17, 2026 |
| CVE-2026-74875 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove … | Aug 17, 2026 |
| CVE-2026-74874 | HIGH | 7.5 | openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in the generate_pseudorandom_sequence function. Attackers who know the password can recover the … | Aug 17, 2026 |
| CVE-2026-74873 | MEDIUM | 5.5 | openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings accessible to all system users. Attackers can read process arguments … | Aug 17, 2026 |
| CVE-2026-74872 | CRITICAL | 9.8 | openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without … | Aug 17, 2026 |
| CVE-2026-74871 | MEDIUM | 6.2 | openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last stage cancels out during key generation. When configured … | Aug 17, 2026 |
| CVE-2026-74870 | LOW | 3.3 | openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hsm onlykey-test' diagnostic commands unconditionally print the full derived hardware … | Aug 17, 2026 |
| CVE-2026-74869 | HIGH | 7.7 | stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message handler that allows authenticated attackers to enumerate members and monitor profile updates of … | Aug 17, 2026 |
| CVE-2026-74868 | HIGH | 7.5 | SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service Basic Auth implementation (PublishServiceTransport.RoundTrip() in kernel/server/proxy/publish.go). The Publish Service runs on a … | Aug 17, 2026 |
| CVE-2026-74867 | MEDIUM | 4.2 | SiYuan versions before 3.7.4 contain a cross-site request forgery vulnerability in the session-cookie authentication branch of CheckAuth() that lacks Origin/Referer validation and sets no explicit … | Aug 17, 2026 |
| CVE-2026-74842 | MEDIUM | 6.3 | A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e19a5415d11a531088170d7b81452. Affected is the function download_image of the file server.py of the component Image-Toolkit-MCP-Server. Performing a … | Aug 17, 2026 |
| CVE-2026-74802 | HIGH | 8.2 | SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-only /ws/network/proxy endpoint that explicitly disables origin validation by setting CheckOrigin to unconditionally … | Aug 17, 2026 |
| CVE-2026-74801 | HIGH | 8.2 | SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the elevated elevator.exe helper process. Attackers can create a malicious … | Aug 17, 2026 |
| CVE-2026-74800 | CRITICAL | 9.0 | SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML … | Aug 17, 2026 |