Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49177
Total
3940
Critical
14579
High
14345
Medium
CVE ID Severity Score Description Published
CVE-2026-47662 UNKNOWN Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of … Aug 07, 2026
CVE-2026-46358 UNKNOWN OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth … Aug 07, 2026
CVE-2026-19246 MEDIUM 6.3 A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function _download_image_data_url of the file nanobot/providers/image_generation.py of the component Provider-returned Image … Aug 07, 2026
CVE-2026-19245 LOW 3.3 A flaw has been found in HKUDS nanobot up to 0.2.1. The impacted element is the function ExecTool._prepare_command of the file nanobot/agent/tools/shell.py of the component … Aug 07, 2026
CVE-2026-19244 MEDIUM 4.7 A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affected element is the function connect_mcp_servers of the file nanobot/agent/tools/mcp.py of the component MCP … Aug 07, 2026
CVE-2026-11425 MEDIUM 4.4 Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allows authenticated attackers to inject arbitrary HTML and JavaScript … Aug 07, 2026
CVE-2026-71870 UNKNOWN pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses … Aug 07, 2026
CVE-2026-66151 UNKNOWN SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local … Aug 07, 2026
CVE-2026-65819 HIGH 7.5 gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffers, … Aug 07, 2026
CVE-2026-62296 HIGH 7.5 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting … Aug 07, 2026
CVE-2026-62295 HIGH 7.5 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser … Aug 07, 2026
CVE-2026-62293 MEDIUM 5.0 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the hidden scan command concatenates attacker-controlled … Aug 07, 2026
CVE-2026-61808 CRITICAL 9.8 LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing … Aug 07, 2026
CVE-2026-48039 CRITICAL 9.1 Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally … Aug 07, 2026
CVE-2026-48007 UNKNOWN Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, when configured to by a … Aug 07, 2026
CVE-2026-47661 UNKNOWN Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of … Aug 07, 2026
CVE-2026-47660 UNKNOWN Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of … Aug 07, 2026
CVE-2026-47659 UNKNOWN Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of … Aug 07, 2026
CVE-2026-19243 MEDIUM 6.3 A security vulnerability has been detected in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component Shell … Aug 07, 2026
CVE-2026-19113 MEDIUM 5.3 Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API endpoints. A remote … Aug 07, 2026
CVE-2026-19017 MEDIUM 6.8 Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA … Aug 07, 2026
CVE-2026-19016 MEDIUM 4.2 Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. … Aug 07, 2026
CVE-2026-19015 MEDIUM 5.3 Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roots endpoint that may … Aug 07, 2026
CVE-2026-19014 MEDIUM 4.3 Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect authorization endpoint that may allow … Aug 07, 2026
CVE-2026-19012 MEDIUM 5.3 Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service in the Enterprise-to-Community Edition downgrade path that may … Aug 07, 2026