Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41987
Total
3420
Critical
12405
High
12324
Medium
CVE ID Severity Score Description Published
CVE-2026-49830 MEDIUM 4.4 DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, when ingesting … Sep 02, 2026
CVE-2026-49249 UNKNOWN Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.10.0, BorutaIdentityWeb.UserSettingsController.update/2 … Sep 02, 2026
CVE-2026-84811 MEDIUM 6.5 agentverus-scanner fails to analyze compiled Python bytecode files in companion code directories, allowing attackers to bypass security scanning by shipping malicious __pycache__ entries alongside benign … Sep 02, 2026
CVE-2026-84810 MEDIUM 6.5 claude-skill-antivirus fails to analyze executable files when scanning local skill directories, reading only SKILL.md while ignoring Python source, bytecode, and other artifacts in the scripts … Sep 02, 2026
CVE-2026-84809 MEDIUM 6.5 Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces. … Sep 02, 2026
CVE-2026-84376 UNKNOWN Astro is a web framework for content-driven websites. Prior to 7.2.4, Astro stripped a configured non-root base path from request pathnames using a string-prefix check … Sep 02, 2026
CVE-2026-82404 HIGH 8.3 TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype key … Sep 02, 2026
CVE-2026-79756 UNKNOWN Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, the fix for unauthenticated OS command injection in the nuclio … Sep 02, 2026
CVE-2026-79755 HIGH 8.0 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, on the Nuclio local Docker platform, the function namespace is … Sep 02, 2026
CVE-2026-79754 UNKNOWN Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. From version 1.6.19 to before version 1.17.2, Nuclio's Dashboard build pipeline does not sanitize … Sep 02, 2026
CVE-2026-55421 MEDIUM 6.8 Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 00b7c3c, the endpoint accepts user-supplied files[].url, performs a … Sep 02, 2026
CVE-2026-53636 MEDIUM 4.7 Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 3a5ac85, a security vulnerability has been identified in … Sep 02, 2026
CVE-2026-53635 HIGH 7.6 Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 59bb6d6, the view function set_course_mode_price() at lms/djangoapps/instructor/views/instructor_dashboard.py:430 is … Sep 02, 2026
CVE-2026-52833 HIGH 8.0 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function builds … Sep 02, 2026
CVE-2026-52832 MEDIUM 4.9 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio Dashboard exposes POST /api/functions without authentication by default (NOP … Sep 02, 2026
CVE-2026-52831 HIGH 8.0 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each … Sep 02, 2026
CVE-2026-45730 HIGH 8.3 Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0, there is a vulnerability in Nuclio Dashboard's project management API, … Sep 02, 2026
CVE-2026-20355 MEDIUM 5.9 Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text … Sep 02, 2026
CVE-2026-20354 MEDIUM 5.9 Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text … Sep 02, 2026
CVE-2026-20281 HIGH 7.5 A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session … Sep 02, 2026
CVE-2026-20280 HIGH 8.8 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. … Sep 02, 2026
CVE-2026-20279 CRITICAL 9.8 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … Sep 02, 2026
CVE-2026-20278 HIGH 8.8 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … Sep 02, 2026
CVE-2026-20277 HIGH 8.2 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … Sep 02, 2026
CVE-2026-20276 HIGH 8.6 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … Sep 02, 2026