Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42140
Total
3430
Critical
12454
High
12396
Medium
CVE ID Severity Score Description Published
CVE-2026-84267 MEDIUM 4.3 A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer … Sep 01, 2026
CVE-2026-84232 MEDIUM 5.4 A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for … Sep 01, 2026
CVE-2026-84207 MEDIUM 5.4 Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send and WebSocket Trigger nodes, allowing authenticated users to connect to internal services. Attackers … Sep 01, 2026
CVE-2026-84206 MEDIUM 4.3 Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. … Sep 01, 2026
CVE-2026-84205 MEDIUM 6.5 GROWI contains an access control vulnerability in the GET /_api/v3/revisions/:id endpoint that validates access against a query parameter but returns the revision identified by the … Sep 01, 2026
CVE-2026-84204 MEDIUM 6.5 GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from … Sep 01, 2026
CVE-2026-84203 HIGH 8.1 Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with … Sep 01, 2026
CVE-2026-84202 HIGH 8.8 ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories … Sep 01, 2026
CVE-2026-84201 HIGH 7.1 appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch tools, allowing attackers to write files outside the intended PROJECT_ROOT … Sep 01, 2026
CVE-2026-84153 MEDIUM 6.3 A vulnerability was determined in Xinhu Rainrock RockOA up to 2.3.2. The impacted element is the function toaddval of the file /index.php?m=index&a=publicsavevalue&ajaxbool=true. Executing a manipulation … Sep 01, 2026
CVE-2026-79687 CRITICAL 9.0 Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem … Sep 01, 2026
CVE-2026-79682 HIGH 8.8 Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges. Sep 01, 2026
CVE-2026-61779 HIGH 7.8 NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … Sep 01, 2026
CVE-2026-61778 HIGH 7.8 NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … Sep 01, 2026
CVE-2026-61777 HIGH 7.8 NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … Sep 01, 2026
CVE-2026-61776 HIGH 7.8 NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … Sep 01, 2026
CVE-2026-61775 HIGH 7.8 NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … Sep 01, 2026
CVE-2026-61774 HIGH 7.8 NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … Sep 01, 2026
CVE-2026-61773 HIGH 7.8 NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … Sep 01, 2026
CVE-2026-61772 HIGH 7.8 NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … Sep 01, 2026
CVE-2026-61771 HIGH 7.8 NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … Sep 01, 2026
CVE-2026-61770 HIGH 7.8 NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … Sep 01, 2026
CVE-2026-61769 HIGH 7.8 NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … Sep 01, 2026
CVE-2026-61768 HIGH 7.8 NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … Sep 01, 2026
CVE-2026-61767 HIGH 7.8 NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to … Sep 01, 2026