Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48891
Total
3931
Critical
14494
High
14248
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-11735 | UNKNOWN | — | A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality. | Aug 11, 2026 |
| CVE-2026-11734 | UNKNOWN | — | A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable. | Aug 11, 2026 |
| CVE-2026-11733 | UNKNOWN | — | A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device. | Aug 11, 2026 |
| CVE-2025-31114 | UNKNOWN | — | Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe … | Aug 11, 2026 |
| CVE-2026-73067 | UNKNOWN | — | Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init can cause SquishedDawg::read_squished_dawg in src/dict/dawg.cpp to accept an … | Aug 11, 2026 |
| CVE-2026-73066 | UNKNOWN | — | Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed … | Aug 11, 2026 |
| CVE-2026-72925 | MEDIUM | 6.1 | SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized … | Aug 11, 2026 |
| CVE-2026-72922 | HIGH | 8.2 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's autogpt_platform/backend/backend/api/features/integrations/router.py webhook_ingress_generic route selected get_webhook_manager(provider) from … | Aug 11, 2026 |
| CVE-2026-72921 | HIGH | 8.1 | SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped … | Aug 11, 2026 |
| CVE-2026-72920 | CRITICAL | 9.8 | SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any … | Aug 11, 2026 |
| CVE-2026-47702 | UNKNOWN | — | TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the database … | Aug 11, 2026 |
| CVE-2026-18860 | HIGH | 8.7 | Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same … | Aug 11, 2026 |
| CVE-2026-18636 | MEDIUM | 6.8 | The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other … | Aug 11, 2026 |
| CVE-2026-18635 | HIGH | 7.2 | Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as … | Aug 11, 2026 |
| CVE-2026-18129 | HIGH | 8.1 | Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position … | Aug 11, 2026 |
| CVE-2026-18127 | HIGH | 7.7 | External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over … | Aug 11, 2026 |
| CVE-2026-18125 | HIGH | 7.5 | An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service. | Aug 11, 2026 |
| CVE-2026-17535 | MEDIUM | 6.2 | Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS … | Aug 11, 2026 |
| CVE-2026-17061 | CRITICAL | 10.0 | A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution. | Aug 11, 2026 |
| CVE-2023-54374 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected. | Aug 11, 2026 |
| CVE-2023-54373 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected. | Aug 11, 2026 |
| CVE-2023-54372 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected. | Aug 11, 2026 |
| CVE-2023-54371 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected. | Aug 11, 2026 |
| CVE-2023-54370 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected. | Aug 11, 2026 |
| CVE-2023-54369 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected. | Aug 11, 2026 |