Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41987
Total
3420
Critical
12405
High
12324
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-49830 | MEDIUM | 4.4 | DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, when ingesting … | Sep 02, 2026 |
| CVE-2026-49249 | UNKNOWN | — | Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.10.0, BorutaIdentityWeb.UserSettingsController.update/2 … | Sep 02, 2026 |
| CVE-2026-84811 | MEDIUM | 6.5 | agentverus-scanner fails to analyze compiled Python bytecode files in companion code directories, allowing attackers to bypass security scanning by shipping malicious __pycache__ entries alongside benign … | Sep 02, 2026 |
| CVE-2026-84810 | MEDIUM | 6.5 | claude-skill-antivirus fails to analyze executable files when scanning local skill directories, reading only SKILL.md while ignoring Python source, bytecode, and other artifacts in the scripts … | Sep 02, 2026 |
| CVE-2026-84809 | MEDIUM | 6.5 | Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces. … | Sep 02, 2026 |
| CVE-2026-84376 | UNKNOWN | — | Astro is a web framework for content-driven websites. Prior to 7.2.4, Astro stripped a configured non-root base path from request pathnames using a string-prefix check … | Sep 02, 2026 |
| CVE-2026-82404 | HIGH | 8.3 | TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype key … | Sep 02, 2026 |
| CVE-2026-79756 | UNKNOWN | — | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, the fix for unauthenticated OS command injection in the nuclio … | Sep 02, 2026 |
| CVE-2026-79755 | HIGH | 8.0 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, on the Nuclio local Docker platform, the function namespace is … | Sep 02, 2026 |
| CVE-2026-79754 | UNKNOWN | — | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. From version 1.6.19 to before version 1.17.2, Nuclio's Dashboard build pipeline does not sanitize … | Sep 02, 2026 |
| CVE-2026-55421 | MEDIUM | 6.8 | Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 00b7c3c, the endpoint accepts user-supplied files[].url, performs a … | Sep 02, 2026 |
| CVE-2026-53636 | MEDIUM | 4.7 | Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 3a5ac85, a security vulnerability has been identified in … | Sep 02, 2026 |
| CVE-2026-53635 | HIGH | 7.6 | Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 59bb6d6, the view function set_course_mode_price() at lms/djangoapps/instructor/views/instructor_dashboard.py:430 is … | Sep 02, 2026 |
| CVE-2026-52833 | HIGH | 8.0 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function builds … | Sep 02, 2026 |
| CVE-2026-52832 | MEDIUM | 4.9 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio Dashboard exposes POST /api/functions without authentication by default (NOP … | Sep 02, 2026 |
| CVE-2026-52831 | HIGH | 8.0 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each … | Sep 02, 2026 |
| CVE-2026-45730 | HIGH | 8.3 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0, there is a vulnerability in Nuclio Dashboard's project management API, … | Sep 02, 2026 |
| CVE-2026-20355 | MEDIUM | 5.9 | Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text … | Sep 02, 2026 |
| CVE-2026-20354 | MEDIUM | 5.9 | Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text … | Sep 02, 2026 |
| CVE-2026-20281 | HIGH | 7.5 | A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session … | Sep 02, 2026 |
| CVE-2026-20280 | HIGH | 8.8 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. … | Sep 02, 2026 |
| CVE-2026-20279 | CRITICAL | 9.8 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … | Sep 02, 2026 |
| CVE-2026-20278 | HIGH | 8.8 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … | Sep 02, 2026 |
| CVE-2026-20277 | HIGH | 8.2 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … | Sep 02, 2026 |
| CVE-2026-20276 | HIGH | 8.6 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … | Sep 02, 2026 |