Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49358
Total
3967
Critical
14633
High
14397
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-71435 | MEDIUM | 6.1 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") form notification email rendered user-submitted values … | Aug 06, 2026 |
| CVE-2026-71434 | MEDIUM | 5.3 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms did not enforce the file upload … | Aug 06, 2026 |
| CVE-2026-71433 | MEDIUM | 5.3 | LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite packages persisted … | Aug 06, 2026 |
| CVE-2026-71430 | MEDIUM | 6.2 | node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using … | Aug 06, 2026 |
| CVE-2026-71327 | UNKNOWN | — | Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, … | Aug 06, 2026 |
| CVE-2026-71326 | UNKNOWN | — | Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password … | Aug 06, 2026 |
| CVE-2026-71325 | UNKNOWN | — | Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are … | Aug 06, 2026 |
| CVE-2026-71324 | UNKNOWN | — | Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default HTTP reverse proxy forwards a plain … | Aug 06, 2026 |
| CVE-2026-70640 | HIGH | 7.0 | llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and free_1context() lack synchronization, allowing Thread A … | Aug 06, 2026 |
| CVE-2026-70639 | MEDIUM | 5.5 | llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper where the bench_1model() function fails to validate the model … | Aug 06, 2026 |
| CVE-2026-70638 | HIGH | 7.8 | llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max … | Aug 06, 2026 |
| CVE-2026-70636 | HIGH | 7.5 | Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in … | Aug 06, 2026 |
| CVE-2026-70635 | HIGH | 7.1 | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated attackers to cause query-result integrity failures or backend crashes by … | Aug 06, 2026 |
| CVE-2026-70634 | HIGH | 8.1 | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded … | Aug 06, 2026 |
| CVE-2026-70633 | MEDIUM | 6.5 | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compression reverse row iterator that allows authenticated attackers to cause … | Aug 06, 2026 |
| CVE-2026-70632 | HIGH | 7.8 | FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that … | Aug 06, 2026 |
| CVE-2026-70631 | MEDIUM | 5.5 | FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An … | Aug 06, 2026 |
| CVE-2026-70630 | MEDIUM | 5.5 | FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows … | Aug 06, 2026 |
| CVE-2026-70629 | MEDIUM | 5.5 | FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows … | Aug 06, 2026 |
| CVE-2026-70628 | HIGH | 7.8 | FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows … | Aug 06, 2026 |
| CVE-2026-70559 | HIGH | 7.5 | Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-level @SaCheckLogin, so the Sa-Token interceptor lets the request through with … | Aug 06, 2026 |
| CVE-2026-70558 | CRITICAL | 9.8 | Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and … | Aug 06, 2026 |
| CVE-2026-70557 | MEDIUM | 6.5 | diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of any entity and returns those values for all rows, with no field … | Aug 06, 2026 |
| CVE-2026-69125 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67321. Reason: This candidate is a duplicate of CVE-2026-67321. Notes: All CVE users … | Aug 06, 2026 |
| CVE-2026-69124 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67320. Reason: This candidate is a duplicate of CVE-2026-67320. Notes: All CVE users … | Aug 06, 2026 |