Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42140
Total
3430
Critical
12454
High
12396
Medium
CVE ID Severity Score Description Published
CVE-2026-84304 UNKNOWN gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so … Sep 01, 2026
CVE-2026-84303 UNKNOWN gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in … Sep 01, 2026
CVE-2026-83551 HIGH 7.2 Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an … Sep 01, 2026
CVE-2026-81846 LOW 3.5 An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through … Sep 01, 2026
CVE-2026-52295 UNKNOWN Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows an attacker to cause a denial of service via the libavformat/iamf_writer.c component Sep 01, 2026
CVE-2026-52132 HIGH 7.5 llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a … Sep 01, 2026
CVE-2026-52131 UNKNOWN llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function. Sep 01, 2026
CVE-2026-52130 HIGH 7.5 llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to-grammar.cpp, resulting in a denial of service. Sep 01, 2026
CVE-2026-52111 CRITICAL 9.8 An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes authTokenKey Sep 01, 2026
CVE-2026-52023 UNKNOWN An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path … Sep 01, 2026
CVE-2026-52022 UNKNOWN An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registration handling components Sep 01, 2026
CVE-2026-51974 UNKNOWN An eval() injection vulnerability in the get_list function in modules/meta_parser.py in lllyasviel Fooocus 2.1.854 through 2.5.5 allows remote attackers to execute arbitrary Python code via … Sep 01, 2026
CVE-2026-19593 UNKNOWN OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a … Sep 01, 2026
CVE-2026-19592 HIGH 7.3 OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS automatically collected Git repository metadata without disabling the repository-local core.fsmonitor … Sep 01, 2026
CVE-2026-19591 UNKNOWN OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser … Sep 01, 2026
CVE-2026-19590 UNKNOWN OpenAI Codex Desktop for Windows and macOS could execute attacker-controlled Git hooks because automated Git operations trusted the repository's local core.hooksPath setting. If a user … Sep 01, 2026
CVE-2024-7953 UNKNOWN A vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a … Sep 01, 2026
CVE-2024-7952 UNKNOWN A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be … Sep 01, 2026
CVE-2026-58566 HIGH 8.8 Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. Sep 01, 2026
CVE-2026-51956 HIGH 8.1 A Broken Object Level Authorization vulnerability exists in Grashjs Atlas CMMS prior to v1.6.0. An authenticated user from one tenant can read and modify another … Sep 01, 2026
CVE-2026-51934 CRITICAL 9.8 Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co., Ltd. Tenda A18 v.15.13.07.09 allows a remote attacker to execute arbitrary code via the fromSetCmdlineRun function Sep 01, 2026
CVE-2026-51788 UNKNOWN An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification function and the accounts/models.py component Sep 01, 2026
CVE-2026-84270 MEDIUM 4.3 A flaw was found in the MTP backend in gvfs. When reading a file from a mounted MTP device, do_read() in gvfsbackendmtp.c trusts the data … Sep 01, 2026
CVE-2026-84269 MEDIUM 6.5 A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to … Sep 01, 2026
CVE-2026-84268 HIGH 8.8 A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() … Sep 01, 2026