Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47944
Total
3850
Critical
14243
High
13921
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-14664 | HIGH | 8.8 | Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that … | Aug 13, 2026 |
| CVE-2026-14663 | MEDIUM | 6.5 | Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL … | Aug 13, 2026 |
| CVE-2026-14662 | HIGH | 8.8 | Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write … | Aug 13, 2026 |
| CVE-2025-52640 | MEDIUM | 4.7 | HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage … | Aug 13, 2026 |
| CVE-2026-73629 | HIGH | 8.5 | Serendipity before 2.6.0 contains a server-side request forgery vulnerability in the serendipity_url_allowed() filter that fails to block hex-encoded IPv4 addresses, IPv6 literals, and link-local ranges. … | Aug 13, 2026 |
| CVE-2026-73628 | MEDIUM | 6.1 | Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-site scripting vulnerability in the search clean-URL route (/search/<term>). In include/functions_routing.inc.php serveSearch(), the sanitisation pipeline … | Aug 13, 2026 |
| CVE-2026-73627 | UNKNOWN | — | JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 contain a plugin manager lock-rule enforcement bypass. Two server-side enforcement gaps allow an authenticated user to circumvent … | Aug 13, 2026 |
| CVE-2026-73626 | NONE | — | JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension … | Aug 13, 2026 |
| CVE-2026-73625 | HIGH | 8.8 | GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling git options inside single-character kwarg … | Aug 13, 2026 |
| CVE-2026-73624 | HIGH | 8.1 | GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can … | Aug 13, 2026 |
| CVE-2026-73623 | HIGH | 7.5 | GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply … | Aug 13, 2026 |
| CVE-2026-73622 | HIGH | 7.5 | GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to exfiltrate secrets by supplying URLs containing variable … | Aug 13, 2026 |
| CVE-2026-73621 | MEDIUM | 5.4 | GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list' without the check_unsafe_options guard present in … | Aug 13, 2026 |
| CVE-2026-73620 | HIGH | 8.1 | GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe options via kwargs. Attackers can use --prefix … | Aug 13, 2026 |
| CVE-2026-73619 | MEDIUM | 6.5 | GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options. Attackers can supply these options to Repo.archive() to … | Aug 13, 2026 |
| CVE-2026-73618 | HIGH | 8.3 | Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied parameters are interpolated into JSON query templates without … | Aug 13, 2026 |
| CVE-2026-73617 | HIGH | 7.1 | Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB datasource integration where user-supplied parameters are enriched with handlebars using noEscaping: true and parsed … | Aug 13, 2026 |
| CVE-2026-73616 | MEDIUM | 6.5 | OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in … | Aug 13, 2026 |
| CVE-2026-73615 | HIGH | 8.8 | Network-AI versions before 5.15.1 contain a security matcher bypass vulnerability where SandboxPolicy evaluates raw command strings with quotes preserved while the executor tokenizes commands by … | Aug 13, 2026 |
| CVE-2026-73614 | HIGH | 8.8 | Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns, while Claude Code executes the full untruncated command. Attackers can position … | Aug 13, 2026 |
| CVE-2026-73613 | HIGH | 8.2 | filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction mechanism that allows authenticated users with only Create permission … | Aug 13, 2026 |
| CVE-2026-73612 | HIGH | 8.1 | File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access … | Aug 13, 2026 |
| CVE-2026-73611 | MEDIUM | 6.8 | File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a … | Aug 13, 2026 |
| CVE-2026-73610 | MEDIUM | 5.8 | SiYuan before v3.7.4 contains an information disclosure vulnerability in the local storage filter that returns the administrator's entire storage map with only three keys sanitized. … | Aug 13, 2026 |
| CVE-2026-73609 | MEDIUM | 5.8 | SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in the workspace without publish-access filtering. Anonymous … | Aug 13, 2026 |