Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49645
Total
4014
Critical
14740
High
14481
Medium
CVE ID Severity Score Description Published
CVE-2026-64584 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: cancel pending IN work before freeing the midi object The f_midi driver … Aug 06, 2026
CVE-2026-64583 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown The Broadcom BDC UDC … Aug 06, 2026
CVE-2026-5430 CRITICAL 10.0 The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with … Aug 06, 2026
CVE-2026-1728 CRITICAL 9.8 Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability … Aug 06, 2026
CVE-2026-19021 HIGH 7.3 A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by this issue is some unknown functionality of the file … Aug 06, 2026
CVE-2026-19020 MEDIUM 6.3 A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /servicetype.php. This manipulation … Aug 06, 2026
CVE-2026-19019 MEDIUM 4.8 A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_session_persistence of the file executor/app/core/workspace.py of the component Claude … Aug 06, 2026
CVE-2026-19011 MEDIUM 5.3 A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function buildSystemPrompt of the file packages/server/src/routes/agents.ts. Performing a manipulation results in file inclusion. … Aug 06, 2026
CVE-2026-19010 HIGH 7.3 A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packages/main/src/index.ts of the component Message API Endpoint. Such … Aug 06, 2026
CVE-2026-19009 HIGH 7.3 A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core/src/response.ts of the component Message API Endpoint. This … Aug 06, 2026
CVE-2026-19008 MEDIUM 6.3 A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape of the file src/agents/sandbox-paths.ts of the component apply_patch Tool. … Aug 06, 2026
CVE-2026-18915 MEDIUM 5.0 Invocation of process using visible sensitive information vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute eta-otp-lock allows System Footprinting. This issue affects eta-otp-lock: before 1.0.4. Aug 06, 2026
CVE-2026-18649 HIGH 7.5 A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size limit on the … Aug 06, 2026
CVE-2026-18597 HIGH 8.5 The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could trigger an SSRF … Aug 06, 2026
CVE-2026-0637 MEDIUM 4.4 When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization … Aug 06, 2026
CVE-2025-15039 CRITICAL 9.4 The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators … Aug 06, 2026
CVE-2025-14779 LOW 3.8 The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delete cascade logic, when triggered, fails to … Aug 06, 2026
CVE-2025-13909 MEDIUM 4.3 The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OTP, SMS OTP, or Magic Link as first-factor authenticators. This … Aug 06, 2026
CVE-2025-13736 LOW 3.7 When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. For valid users, the server resolves and displays … Aug 06, 2026
CVE-2025-13394 MEDIUM 5.4 The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Specifically, it utilizes the HTTP GET … Aug 06, 2026
CVE-2025-12627 LOW 2.4 The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated sessions. This allows an attacker who has obtained … Aug 06, 2026
CVE-2025-11850 MEDIUM 4.3 When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary user store and bypasses the primary user store during search and … Aug 06, 2026
CVE-2024-8995 MEDIUM 4.9 Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, … Aug 06, 2026
CVE-2024-6832 MEDIUM 5.9 The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if … Aug 06, 2026
CVE-2024-10302 MEDIUM 4.0 The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user … Aug 06, 2026