Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
29364
Total
2293
Critical
8785
High
9139
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-43996 | MEDIUM | 5.5 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and … | May 14, 2026 |
| CVE-2026-43909 | HIGH | 8.8 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and … | May 14, 2026 |
| CVE-2026-43908 | HIGH | 8.8 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and … | May 14, 2026 |
| CVE-2026-43907 | HIGH | 8.3 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and … | May 14, 2026 |
| CVE-2026-43906 | UNKNOWN | — | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and … | May 14, 2026 |
| CVE-2026-43905 | UNKNOWN | — | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and … | May 14, 2026 |
| CVE-2026-43904 | UNKNOWN | — | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and … | May 14, 2026 |
| CVE-2026-43903 | UNKNOWN | — | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and … | May 14, 2026 |
| CVE-2026-3290 | UNKNOWN | — | Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values | May 14, 2026 |
| CVE-2026-26191 | UNKNOWN | — | Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer pipeline could allow a crafted software package to … | May 14, 2026 |
| CVE-2026-26062 | UNKNOWN | — | Fleet is open source device management software. Prior to version 4.81.0, Fleet contained a denial-of-service (DoS) issue in the gRPC Launcher `PublishLogs` endpoint. In affected … | May 14, 2026 |
| CVE-2026-24899 | UNKNOWN | — | Fleet is open source device management software. Prior to version 4.82.0, a vulnerability in Fleet's Windows MDM enrollment flow allows authentication tokens from any Azure … | May 14, 2026 |
| CVE-2026-24000 | UNKNOWN | — | Fleet is open source device management software. Prior to version 4.80.1, Fleet trusted client-supplied IP address headers when determining the source IP for incoming requests. … | May 14, 2026 |
| CVE-2026-8621 | HIGH | 8.8 | Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers. Attackers … | May 14, 2026 |
| CVE-2026-45375 | CRITICAL | 9.0 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan's Bazaar (community marketplace) renders the name and version fields of a package's plugin.json … | May 14, 2026 |
| CVE-2026-45371 | UNKNOWN | — | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs. POST … | May 14, 2026 |
| CVE-2026-45148 | MEDIUM | 4.3 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, broken access control in the searchAsset, searchTag, searchWidget, and searchTemplate publish-mode Readers can enumerate … | May 14, 2026 |
| CVE-2026-45147 | MEDIUM | 4.3 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, POST /api/tag/getTag is registered with model.CheckAuth only, omitting both model.CheckAdminRole and model.CheckReadonly, despite the … | May 14, 2026 |
| CVE-2026-44670 | UNKNOWN | — | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / database) names without any HTML escape, then … | May 14, 2026 |
| CVE-2026-44633 | HIGH | 8.1 | Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST API chat update endpoint allows a … | May 14, 2026 |
| CVE-2026-44592 | CRITICAL | 9.4 | Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the NixOS module default), anyone who can reach /proto can register … | May 14, 2026 |
| CVE-2026-44589 | LOW | 3.7 | Nuxt OG Image generates OG Images with Vue templates in Nuxt. The isBlockedUrl() denylist introduced in nuxt-og-image@6.2.5 to remediate GHSA-pqhr-mp3f-hrpp (Dmitry Prokhorov / Positive Technologies, … | May 14, 2026 |
| CVE-2026-44588 | UNKNOWN | — | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, he tooltip mouseover handler in app/src/block/popover.ts reads aria-label via getAttribute and passes it through … | May 14, 2026 |
| CVE-2026-44586 | HIGH | 8.3 | SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metadata from the public bazaar stage … | May 14, 2026 |
| CVE-2026-44523 | CRITICAL | 10.0 | Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JWT_SECRET configuration value. The application accepts … | May 14, 2026 |