Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41987
Total
3420
Critical
12405
High
12324
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-84840 | MEDIUM | 6.5 | A vulnerability was identified in tsi-coop tsi-dpdp-cms up to 0.5.0. This affects an unknown part of the file InterceptingFilter.java of the component Bootstrap Setup Endpoint. … | Sep 02, 2026 |
| CVE-2026-84839 | MEDIUM | 5.3 | A vulnerability was determined in tsi-coop tsi-dpdp-cms up to 0.5.0. Affected by this issue is some unknown functionality of the file web.xml of the component … | Sep 02, 2026 |
| CVE-2026-84382 | HIGH | 7.5 | HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or … | Sep 02, 2026 |
| CVE-2026-84381 | HIGH | 8.1 | HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin … | Sep 02, 2026 |
| CVE-2026-19117 | CRITICAL | 9.8 | Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises … | Sep 02, 2026 |
| CVE-2026-84833 | MEDIUM | 4.3 | A vulnerability was found in ntegrals openbrowser up to 067fc45d649baa961750da8e2f4a75d87c5c75c8. Affected by this vulnerability is an unknown functionality of the file packages/core/src/agent/agent.ts of the component … | Sep 02, 2026 |
| CVE-2026-84380 | MEDIUM | 5.6 | HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Content-Length header to a request that … | Sep 02, 2026 |
| CVE-2026-84379 | MEDIUM | 5.3 | HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py directly interpolates attacker-controlled content_type values and custom headers from the … | Sep 02, 2026 |
| CVE-2026-84378 | MEDIUM | 5.9 | HTTPX2 is a next generation HTTP client for Python. From 2.5.0 until 2.10.0, the HTTPX2 Server-Sent Events parser in src/httpx2/httpx2/_sse.py repeatedly copies and rescans buffered … | Sep 02, 2026 |
| CVE-2026-84377 | MEDIUM | 6.5 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteLLM … | Sep 02, 2026 |
| CVE-2026-82522 | MEDIUM | 5.4 | libjxl before 0.12 contains an integer underflow vulnerability in the container box parser that allows remote attackers to inject arbitrary metadata by exploiting 64-bit box … | Sep 02, 2026 |
| CVE-2026-77125 | UNKNOWN | — | A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did not correctly enforce the intended authorization … | Sep 02, 2026 |
| CVE-2026-77124 | UNKNOWN | — | In affected versions of Nexus Repository 3, the script execution endpoint (POST /service/rest/v1/script/{name}/run) did not verify whether script execution had been administratively disabled. An account … | Sep 02, 2026 |
| CVE-2026-77123 | UNKNOWN | — | Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding the nexus:capabilities:read privilege can retrieve the plaintext shared … | Sep 02, 2026 |
| CVE-2026-77122 | UNKNOWN | — | An authorization flaw in the REST API repository details endpoint (GET /service/rest/v1/repositories/{repositoryName}) in Sonatype Nexus Repository 3 allowed an account holding read or browse permission … | Sep 02, 2026 |
| CVE-2026-77121 | UNKNOWN | — | A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes … | Sep 02, 2026 |
| CVE-2026-66786 | CRITICAL | 9.1 | A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper … | Sep 02, 2026 |
| CVE-2026-55221 | MEDIUM | 6.5 | Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.10.0, Boruta … | Sep 02, 2026 |
| CVE-2026-53706 | UNKNOWN | — | PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the prevail eBPF verifier accepts ALU32 ADD and SUB instructions … | Sep 02, 2026 |
| CVE-2026-53671 | UNKNOWN | — | PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the abstract transformer in prevail treats writes through a T_CTX-typed … | Sep 02, 2026 |
| CVE-2026-53670 | UNKNOWN | — | PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, in the Prevail eBPF verifier, EbpfTransformer::add() silently skips offset-variable updates … | Sep 02, 2026 |
| CVE-2026-53649 | CRITICAL | 9.6 | Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and … | Sep 02, 2026 |
| CVE-2026-49833 | MEDIUM | 5.5 | DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, 9.0-rc1 to before 9.3, … | Sep 02, 2026 |
| CVE-2026-49832 | HIGH | 8.0 | DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before … | Sep 02, 2026 |
| CVE-2026-49831 | MEDIUM | 5.5 | DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, the Curation … | Sep 02, 2026 |