Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

28438
Total
2190
Critical
8535
High
8856
Medium
CVE ID Severity Score Description Published
CVE-2026-45571 MEDIUM 5.4 go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted … May 27, 2026
CVE-2026-45570 UNKNOWN go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by … May 27, 2026
CVE-2026-45022 UNKNOWN go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way … May 27, 2026
CVE-2026-44988 HIGH 8.8 LibVNCClient is a library for easy implementation of a VNC client. In 0.9.15 and earlier, LibVNCClient's Tight encoding decoder uses fixed-size 2048-pixel scratch buffers for … May 27, 2026
CVE-2026-44972 MEDIUM 5.0 GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 to 2.9.0, GuardDog includes attacker-controlled filenames, file locations, messages, and code snippets in … May 27, 2026
CVE-2026-44971 HIGH 8.2 GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scanning path rewrites attacker-controlled repository URLs using … May 27, 2026
CVE-2026-44902 HIGH 7.5 opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The … May 27, 2026
CVE-2026-44839 UNKNOWN RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13. May 27, 2026
CVE-2026-44838 UNKNOWN RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level authorization using regular expressions with variable substitution. … May 27, 2026
CVE-2026-44830 UNKNOWN Nocturne Memory is a lightweight, rollbackable, and visual Long-Term Memory Server for MCP Agents. Prior to 2.4.1, when API_TOKEN is unset or empty, the BearerTokenAuthMiddleware … May 27, 2026
CVE-2026-42280 HIGH 7.1 Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return user profile information using … May 27, 2026
CVE-2026-42184 UNKNOWN Tauri is a framework for building binaries for all major desktop platforms. From 2.0 to 2.11.0, a flaw in Tauri's is_local_url() function causes it to … May 27, 2026
CVE-2026-37713 UNKNOWN An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/class/commonobject.class.php. May 27, 2026
CVE-2026-37712 UNKNOWN An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/cron/class/cronjob.class.php, call_user_func_array() in function job … May 27, 2026
CVE-2026-37711 HIGH 7.3 An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/actions_addupdatedelete.inc.php May 27, 2026
CVE-2026-31266 HIGH 7.3 Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate). May 27, 2026
CVE-2026-30498 MEDIUM 6.3 A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the delete.php endpoint of Jason2605 AdminPanel 4.0. May 27, 2026
CVE-2026-1248 MEDIUM 4.3 IBM Business Automation Workflow containers and traditional may leak information about its database structure in error messages. May 27, 2026
CVE-2025-70103 HIGH 7.3 Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc. May 27, 2026
CVE-2026-9704 MEDIUM 6.8 A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JWT) … May 27, 2026
CVE-2026-9617 MEDIUM 6.8 PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and placing malicious code inside a column identifier. … May 27, 2026
CVE-2026-9035 MEDIUM 6.5 IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM … May 27, 2026
CVE-2026-8405 MEDIUM 6.5 IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug … May 27, 2026
CVE-2026-8180 HIGH 7.5 IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM … May 27, 2026
CVE-2026-8179 HIGH 8.8 IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM … May 27, 2026