Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49177
Total
3940
Critical
14579
High
14345
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-47127 | MEDIUM | 6.5 | Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-URL handler at `GET /api/v1/subscription/stripe/callback?checkoutSessionId=<id>` retrieves the Stripe Checkout Session … | Aug 07, 2026 |
| CVE-2026-46409 | CRITICAL | 9.6 | OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend … | Aug 07, 2026 |
| CVE-2025-4438 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 07, 2026 |
| CVE-2026-64676 | MEDIUM | 5.7 | Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 4.0.0, the kata-agent is vulnerable … | Aug 07, 2026 |
| CVE-2026-58262 | UNKNOWN | — | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification counts the unused padding bits of the PubKeysBitmap toward … | Aug 07, 2026 |
| CVE-2026-48170 | CRITICAL | 9.1 | `scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a … | Aug 07, 2026 |
| CVE-2026-48169 | HIGH | 8.8 | PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The … | Aug 07, 2026 |
| CVE-2026-47243 | UNKNOWN | — | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to 3.31.0, the … | Aug 07, 2026 |
| CVE-2026-46405 | MEDIUM | 5.3 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, or when an … | Aug 07, 2026 |
| CVE-2026-45808 | UNKNOWN | — | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers … | Aug 07, 2026 |
| CVE-2026-11743 | MEDIUM | 6.6 | The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash offset and length on its read and write paths with the test (offset + … | Aug 07, 2026 |
| CVE-2026-11742 | LOW | 3.6 | The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue's data_q list, reading the node's flag byte and, for items enqueued … | Aug 07, 2026 |
| CVE-2026-9031 | UNKNOWN | — | An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by internal flash-write handling logic. … | Aug 07, 2026 |
| CVE-2026-9030 | UNKNOWN | — | A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction handlng path in httpd does not properly synchronize or … | Aug 07, 2026 |
| CVE-2026-71381 | MEDIUM | 4.0 | Adobe Genuine Software Integrity Service was affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could have leveraged … | Aug 07, 2026 |
| CVE-2026-70624 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 07, 2026 |
| CVE-2026-70623 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 07, 2026 |
| CVE-2026-69207 | MEDIUM | 5.3 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in CORS middleware, hono/cors, is vulnerable to a … | Aug 07, 2026 |
| CVE-2026-66061 | HIGH | 7.1 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS Companion app treats tag links (NFC … | Aug 07, 2026 |
| CVE-2026-66060 | HIGH | 7.1 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Companion app treats tag links (NFC or … | Aug 07, 2026 |
| CVE-2026-59717 | MEDIUM | 4.3 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Android Companion app is vulnerable to an … | Aug 07, 2026 |
| CVE-2026-54338 | MEDIUM | 5.3 | JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid input to form-based login authenticators can place … | Aug 07, 2026 |
| CVE-2026-50540 | CRITICAL | 9.6 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, … | Aug 07, 2026 |
| CVE-2026-47664 | UNKNOWN | — | Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of … | Aug 07, 2026 |
| CVE-2026-47663 | UNKNOWN | — | Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of … | Aug 07, 2026 |