Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42140
Total
3430
Critical
12454
High
12396
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-84267 | MEDIUM | 4.3 | A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer … | Sep 01, 2026 |
| CVE-2026-84232 | MEDIUM | 5.4 | A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for … | Sep 01, 2026 |
| CVE-2026-84207 | MEDIUM | 5.4 | Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send and WebSocket Trigger nodes, allowing authenticated users to connect to internal services. Attackers … | Sep 01, 2026 |
| CVE-2026-84206 | MEDIUM | 4.3 | Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. … | Sep 01, 2026 |
| CVE-2026-84205 | MEDIUM | 6.5 | GROWI contains an access control vulnerability in the GET /_api/v3/revisions/:id endpoint that validates access against a query parameter but returns the revision identified by the … | Sep 01, 2026 |
| CVE-2026-84204 | MEDIUM | 6.5 | GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from … | Sep 01, 2026 |
| CVE-2026-84203 | HIGH | 8.1 | Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with … | Sep 01, 2026 |
| CVE-2026-84202 | HIGH | 8.8 | ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories … | Sep 01, 2026 |
| CVE-2026-84201 | HIGH | 7.1 | appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch tools, allowing attackers to write files outside the intended PROJECT_ROOT … | Sep 01, 2026 |
| CVE-2026-84153 | MEDIUM | 6.3 | A vulnerability was determined in Xinhu Rainrock RockOA up to 2.3.2. The impacted element is the function toaddval of the file /index.php?m=index&a=publicsavevalue&ajaxbool=true. Executing a manipulation … | Sep 01, 2026 |
| CVE-2026-79687 | CRITICAL | 9.0 | Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem … | Sep 01, 2026 |
| CVE-2026-79682 | HIGH | 8.8 | Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges. | Sep 01, 2026 |
| CVE-2026-61779 | HIGH | 7.8 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … | Sep 01, 2026 |
| CVE-2026-61778 | HIGH | 7.8 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … | Sep 01, 2026 |
| CVE-2026-61777 | HIGH | 7.8 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … | Sep 01, 2026 |
| CVE-2026-61776 | HIGH | 7.8 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … | Sep 01, 2026 |
| CVE-2026-61775 | HIGH | 7.8 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … | Sep 01, 2026 |
| CVE-2026-61774 | HIGH | 7.8 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … | Sep 01, 2026 |
| CVE-2026-61773 | HIGH | 7.8 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … | Sep 01, 2026 |
| CVE-2026-61772 | HIGH | 7.8 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … | Sep 01, 2026 |
| CVE-2026-61771 | HIGH | 7.8 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … | Sep 01, 2026 |
| CVE-2026-61770 | HIGH | 7.8 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … | Sep 01, 2026 |
| CVE-2026-61769 | HIGH | 7.8 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … | Sep 01, 2026 |
| CVE-2026-61768 | HIGH | 7.8 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … | Sep 01, 2026 |
| CVE-2026-61767 | HIGH | 7.8 | NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … | Sep 01, 2026 |