Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42140
Total
3430
Critical
12454
High
12396
Medium
CVE ID Severity Score Description Published
CVE-2026-84642 UNKNOWN The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this could allow certain … Sep 01, 2026
CVE-2026-84641 UNKNOWN A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This … Sep 01, 2026
CVE-2026-84640 UNKNOWN A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, … Sep 01, 2026
CVE-2026-84639 UNKNOWN Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and … Sep 01, 2026
CVE-2026-84637 UNKNOWN Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new … Sep 01, 2026
CVE-2026-84375 HIGH 7.5 js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources … Sep 01, 2026
CVE-2026-84374 HIGH 7.5 Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled $destination supplied through … Sep 01, 2026
CVE-2026-84373 MEDIUM 5.9 Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 and 5.0.0-rc.2, the public mockerPlugin and standalone interceptorPlugin exports in packages/mocker/src/node/interceptorPlugin.ts register the … Sep 01, 2026
CVE-2026-84372 CRITICAL 9.8 Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication … Sep 01, 2026
CVE-2026-84289 MEDIUM 4.3 A vulnerability was found in NousResearch hermes-agent up to 0.18.2. This vulnerability affects the function list_tools of the file tools/mcp_tool.py of the component MCP Tool. … Sep 01, 2026
CVE-2026-84288 MEDIUM 4.3 A vulnerability has been found in NousResearch hermes-agent up to 0.18.2. This affects the function HermesACPAgent.prompt of the file acp_adapter/session.py of the component ACP Prompt … Sep 01, 2026
CVE-2026-83549 HIGH 7.8 Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) … Sep 01, 2026
CVE-2026-83548 CRITICAL 10.0 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially … Sep 01, 2026
CVE-2026-76851 UNKNOWN A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance. Insufficient network isolation allowed malicious … Sep 01, 2026
CVE-2026-75604 CRITICAL 9.0 Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without … Sep 01, 2026
CVE-2026-19118 UNKNOWN A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticated user with write access … Sep 01, 2026
CVE-2026-18730 UNKNOWN A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted … Sep 01, 2026
CVE-2023-54391 CRITICAL 9.8 Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing … Sep 01, 2026
CVE-2026-84470 MEDIUM 6.4 A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level … Sep 01, 2026
CVE-2026-84371 MEDIUM 5.4 ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, … Sep 01, 2026
CVE-2026-84370 HIGH 8.2 SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, … Sep 01, 2026
CVE-2026-84369 MEDIUM 6.1 SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, … Sep 01, 2026
CVE-2026-84368 LOW 3.7 joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.6 and 18.2.5, the @hapi/joi package through 17.1.1 and the successor … Sep 01, 2026
CVE-2026-84367 LOW 3.7 joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.5 and 18.2.4, joi's lib/types/keys.js internals.rename() implementation used by object().rename() permits … Sep 01, 2026
CVE-2026-84366 HIGH 7.4 Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request … Sep 01, 2026