Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49645
Total
4014
Critical
14740
High
14481
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-18839 | LOW | 2.2 | An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who … | Aug 05, 2026 |
| CVE-2026-18411 | HIGH | 8.1 | The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can … | Aug 05, 2026 |
| CVE-2026-17583 | HIGH | 8.4 | The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering … | Aug 05, 2026 |
| CVE-2026-15996 | UNKNOWN | — | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause excessive CPU consumption and exhaust the pool … | Aug 05, 2026 |
| CVE-2026-70618 | MEDIUM | 4.3 | Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user to enumerate complete guild membership by querying the GET /guilds/{guild_id}/roles/{role_id}/member-ids … | Aug 05, 2026 |
| CVE-2026-70617 | HIGH | 8.1 | Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending … | Aug 05, 2026 |
| CVE-2026-70616 | MEDIUM | 6.5 | boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanently exhaust server file descriptors, goroutines, and memory by sending requests … | Aug 05, 2026 |
| CVE-2026-70615 | CRITICAL | 9.9 | boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH … | Aug 05, 2026 |
| CVE-2026-69111 | HIGH | 7.5 | Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP … | Aug 05, 2026 |
| CVE-2026-68746 | UNKNOWN | — | Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to obtain full access to a Livebook server that enforces identity … | Aug 05, 2026 |
| CVE-2026-66885 | UNKNOWN | — | Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's browser session under the attacker's own Livebook Teams identity. When … | Aug 05, 2026 |
| CVE-2026-66881 | UNKNOWN | — | Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with attacker-controlled content to an arbitrary path. A .livemd notebook … | Aug 05, 2026 |
| CVE-2026-66298 | UNKNOWN | — | Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger session-wide keyboard shortcuts, including forced evaluation of all cells and runtime … | Aug 05, 2026 |
| CVE-2026-66297 | UNKNOWN | — | Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev livebook allows command injection into generated deployment setup commands. … | Aug 05, 2026 |
| CVE-2026-55524 | HIGH | 7.5 | PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing … | Aug 05, 2026 |
| CVE-2026-55523 | UNKNOWN | — | PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.web_crawl() function is vulnerable to server-side request forgery. While it validates the initially … | Aug 05, 2026 |
| CVE-2026-55522 | HIGH | 7.8 | PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable … | Aug 05, 2026 |
| CVE-2026-21766 | MEDIUM | 5.4 | The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Under certain very specific use cases and specific configurations, sensitive … | Aug 05, 2026 |
| CVE-2026-18958 | HIGH | 7.3 | A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c. Affected by this vulnerability is an unknown functionality of the file loginCheckTest.php of the component Login. The … | Aug 05, 2026 |
| CVE-2026-18954 | MEDIUM | 5.5 | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate … | Aug 05, 2026 |
| CVE-2026-18953 | HIGH | 8.6 | Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to … | Aug 05, 2026 |
| CVE-2026-17556 | UNKNOWN | — | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including … | Aug 05, 2026 |
| CVE-2026-9205 | HIGH | 7.4 | IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function. | Aug 05, 2026 |
| CVE-2026-9201 | HIGH | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation … | Aug 05, 2026 |
| CVE-2026-9196 | HIGH | 8.1 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated … | Aug 05, 2026 |