Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49177
Total
3940
Critical
14579
High
14345
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-47662 | UNKNOWN | — | Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of … | Aug 07, 2026 |
| CVE-2026-46358 | UNKNOWN | — | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth … | Aug 07, 2026 |
| CVE-2026-19246 | MEDIUM | 6.3 | A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function _download_image_data_url of the file nanobot/providers/image_generation.py of the component Provider-returned Image … | Aug 07, 2026 |
| CVE-2026-19245 | LOW | 3.3 | A flaw has been found in HKUDS nanobot up to 0.2.1. The impacted element is the function ExecTool._prepare_command of the file nanobot/agent/tools/shell.py of the component … | Aug 07, 2026 |
| CVE-2026-19244 | MEDIUM | 4.7 | A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affected element is the function connect_mcp_servers of the file nanobot/agent/tools/mcp.py of the component MCP … | Aug 07, 2026 |
| CVE-2026-11425 | MEDIUM | 4.4 | Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allows authenticated attackers to inject arbitrary HTML and JavaScript … | Aug 07, 2026 |
| CVE-2026-71870 | UNKNOWN | — | pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumption when pypdf/_cmap.py function parse_bfrange parses … | Aug 07, 2026 |
| CVE-2026-66151 | UNKNOWN | — | SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local … | Aug 07, 2026 |
| CVE-2026-65819 | HIGH | 7.5 | gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-controlled lengths, counts, or offsets before validating them against packet buffers, … | Aug 07, 2026 |
| CVE-2026-62296 | HIGH | 7.5 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting … | Aug 07, 2026 |
| CVE-2026-62295 | HIGH | 7.5 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser … | Aug 07, 2026 |
| CVE-2026-62293 | MEDIUM | 5.0 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the hidden scan command concatenates attacker-controlled … | Aug 07, 2026 |
| CVE-2026-61808 | CRITICAL | 9.8 | LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing … | Aug 07, 2026 |
| CVE-2026-48039 | CRITICAL | 9.1 | Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally … | Aug 07, 2026 |
| CVE-2026-48007 | UNKNOWN | — | Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, when configured to by a … | Aug 07, 2026 |
| CVE-2026-47661 | UNKNOWN | — | Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of … | Aug 07, 2026 |
| CVE-2026-47660 | UNKNOWN | — | Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of … | Aug 07, 2026 |
| CVE-2026-47659 | UNKNOWN | — | Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of … | Aug 07, 2026 |
| CVE-2026-19243 | MEDIUM | 6.3 | A security vulnerability has been detected in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component Shell … | Aug 07, 2026 |
| CVE-2026-19113 | MEDIUM | 5.3 | Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API endpoints. A remote … | Aug 07, 2026 |
| CVE-2026-19017 | MEDIUM | 6.8 | Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA … | Aug 07, 2026 |
| CVE-2026-19016 | MEDIUM | 4.2 | Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. … | Aug 07, 2026 |
| CVE-2026-19015 | MEDIUM | 5.3 | Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roots endpoint that may … | Aug 07, 2026 |
| CVE-2026-19014 | MEDIUM | 4.3 | Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect authorization endpoint that may allow … | Aug 07, 2026 |
| CVE-2026-19012 | MEDIUM | 5.3 | Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service in the Enterprise-to-Community Edition downgrade path that may … | Aug 07, 2026 |