Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

47882
Total
3850
Critical
14243
High
13921
Medium
CVE ID Severity Score Description Published
CVE-2026-73649 CRITICAL 9.8 Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only … Aug 13, 2026
CVE-2026-73648 UNKNOWN rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used … Aug 13, 2026
CVE-2026-73647 MEDIUM 5.6 Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/extend/extend.js recursively copied attacker-controlled object keys … Aug 13, 2026
CVE-2026-73645 UNKNOWN OpenZeppelin Confidential Contracts is an experimental library for developing applications on the Zama fhEVM. Prior to 0.3.1, the ERC7984 contract tracked confidential total supply with … Aug 13, 2026
CVE-2026-73644 CRITICAL 9.6 OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not … Aug 13, 2026
CVE-2026-73643 HIGH 7.5 js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2, parsing a small YAML document can take exponential time when an application calls … Aug 13, 2026
CVE-2026-73569 UNKNOWN fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until 5.10.1, src/xmlparser/OrderedObjParser.js processes multiple DOCTYPE declarations within … Aug 13, 2026
CVE-2026-73568 HIGH 7.5 py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxer/yamux/yamux.py reads an attacker-controlled 32-bit DATA … Aug 13, 2026
CVE-2026-73567 CRITICAL 9.1 sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.generateKeyPairHex() path in Node.js uses the … Aug 13, 2026
CVE-2026-73566 HIGH 7.5 node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive … Aug 13, 2026
CVE-2026-73565 MEDIUM 5.3 @hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request to an upgradeWebSocket route with a missing or malformed … Aug 13, 2026
CVE-2026-73564 UNKNOWN frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH exec channel request by adding … Aug 13, 2026
CVE-2026-73563 MEDIUM 4.7 Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registration and client ID metadata document features in the … Aug 13, 2026
CVE-2026-73562 MEDIUM 6.5 Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a user-controlled update … Aug 13, 2026
CVE-2026-73561 HIGH 7.5 Hub is a Node.js WebSocket server and client with added features. Prior to 0.2.16, every incoming unauthenticated WebSocket connection triggers loadDefaultConnectionEventListeners to call requestClientId, which … Aug 13, 2026
CVE-2026-72741 HIGH 8.1 Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another … Aug 13, 2026
CVE-2026-67614 CRITICAL 9.8 CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens … Aug 13, 2026
CVE-2026-67613 MEDIUM 4.9 CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitrary files from the server filesystem by supplying unsanitized file paths … Aug 13, 2026
CVE-2026-19730 MEDIUM 4.2 The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on … Aug 13, 2026
CVE-2026-18428 HIGH 8.8 A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access … Aug 13, 2026
CVE-2026-12908 UNKNOWN Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this … Aug 13, 2026
CVE-2026-12236 MEDIUM 6.5 The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By Type Response received from a remote GATT server during BT_GATT_DISCOVER_STD_CHAR_DESC discovery. … Aug 13, 2026
CVE-2024-58374 HIGH 7.5 Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a … Aug 13, 2026
CVE-2019-25765 HIGH 7.5 ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in … Aug 13, 2026
CVE-2026-73266 HIGH 7.1 A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows … Aug 13, 2026