Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49645
Total
4014
Critical
14740
High
14481
Medium
CVE ID Severity Score Description Published
CVE-2026-18839 LOW 2.2 An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who … Aug 05, 2026
CVE-2026-18411 HIGH 8.1 The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can … Aug 05, 2026
CVE-2026-17583 HIGH 8.4 The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering … Aug 05, 2026
CVE-2026-15996 UNKNOWN A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause excessive CPU consumption and exhaust the pool … Aug 05, 2026
CVE-2026-70618 MEDIUM 4.3 Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user to enumerate complete guild membership by querying the GET /guilds/{guild_id}/roles/{role_id}/member-ids … Aug 05, 2026
CVE-2026-70617 HIGH 8.1 Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending … Aug 05, 2026
CVE-2026-70616 MEDIUM 6.5 boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanently exhaust server file descriptors, goroutines, and memory by sending requests … Aug 05, 2026
CVE-2026-70615 CRITICAL 9.9 boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH … Aug 05, 2026
CVE-2026-69111 HIGH 7.5 Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service components by sending a crafted HTTP … Aug 05, 2026
CVE-2026-68746 UNKNOWN Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to obtain full access to a Livebook server that enforces identity … Aug 05, 2026
CVE-2026-66885 UNKNOWN Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's browser session under the attacker's own Livebook Teams identity. When … Aug 05, 2026
CVE-2026-66881 UNKNOWN Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with attacker-controlled content to an arbitrary path. A .livemd notebook … Aug 05, 2026
CVE-2026-66298 UNKNOWN Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger session-wide keyboard shortcuts, including forced evaluation of all cells and runtime … Aug 05, 2026
CVE-2026-66297 UNKNOWN Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev livebook allows command injection into generated deployment setup commands. … Aug 05, 2026
CVE-2026-55524 HIGH 7.5 PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing … Aug 05, 2026
CVE-2026-55523 UNKNOWN PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.web_crawl() function is vulnerable to server-side request forgery. While it validates the initially … Aug 05, 2026
CVE-2026-55522 HIGH 7.8 PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable … Aug 05, 2026
CVE-2026-21766 MEDIUM 5.4 The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Under certain very specific use cases and specific configurations, sensitive … Aug 05, 2026
CVE-2026-18958 HIGH 7.3 A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c. Affected by this vulnerability is an unknown functionality of the file loginCheckTest.php of the component Login. The … Aug 05, 2026
CVE-2026-18954 MEDIUM 5.5 Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate … Aug 05, 2026
CVE-2026-18953 HIGH 8.6 Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to … Aug 05, 2026
CVE-2026-17556 UNKNOWN A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including … Aug 05, 2026
CVE-2026-9205 HIGH 7.4 IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function. Aug 05, 2026
CVE-2026-9201 HIGH 8.8 IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation … Aug 05, 2026
CVE-2026-9196 HIGH 8.1 IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated … Aug 05, 2026