Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49853
Total
4028
Critical
14819
High
14575
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-18810 | HIGH | 7.3 | A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. … | Aug 04, 2026 |
| CVE-2026-18657 | HIGH | 7.8 | An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a … | Aug 04, 2026 |
| CVE-2026-18656 | HIGH | 7.8 | An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a … | Aug 04, 2026 |
| CVE-2026-16793 | HIGH | 8.8 | An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an … | Aug 04, 2026 |
| CVE-2026-16792 | MEDIUM | 6.1 | An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive … | Aug 04, 2026 |
| CVE-2026-16791 | LOW | 3.9 | A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite … | Aug 04, 2026 |
| CVE-2026-70474 | UNKNOWN | — | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look … | Aug 04, 2026 |
| CVE-2026-70473 | UNKNOWN | — | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert … | Aug 04, 2026 |
| CVE-2026-70472 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled … | Aug 04, 2026 |
| CVE-2026-70471 | UNKNOWN | — | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox … | Aug 04, 2026 |
| CVE-2026-69704 | MEDIUM | 6.5 | Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsanitized input through a GET parameter to the supp() deletion … | Aug 04, 2026 |
| CVE-2026-69703 | CRITICAL | 9.8 | Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw … | Aug 04, 2026 |
| CVE-2026-69702 | MEDIUM | 6.5 | SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated attackers to crash the server by supplying a crafted Zstandard-compressed … | Aug 04, 2026 |
| CVE-2026-68743 | MEDIUM | 5.5 | A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before … | Aug 04, 2026 |
| CVE-2026-66300 | MEDIUM | 5.0 | SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. An attacker can inject arbitrary JavaScript which will execute upon a … | Aug 04, 2026 |
| CVE-2026-49435 | CRITICAL | 9.8 | Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code … | Aug 04, 2026 |
| CVE-2026-47781 | UNKNOWN | — | PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during … | Aug 04, 2026 |
| CVE-2026-47764 | UNKNOWN | — | pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable to path traversal through write_to_fs. InstallDestination.write_to_fs() … | Aug 04, 2026 |
| CVE-2026-13229 | UNKNOWN | — | Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint. | Aug 04, 2026 |
| CVE-2026-0163 | CRITICAL | 9.8 | In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of … | Aug 04, 2026 |
| CVE-2017-20242 | CRITICAL | 9.8 | Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or … | Aug 04, 2026 |
| CVE-2017-20241 | CRITICAL | 9.8 | Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or … | Aug 04, 2026 |
| CVE-2026-70470 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in packages/components/src/pythonCodeValidator.ts can be … | Aug 04, 2026 |
| CVE-2026-69264 | UNKNOWN | — | Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by … | Aug 04, 2026 |
| CVE-2026-47763 | UNKNOWN | — | pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm writes several project-local state or configuration … | Aug 04, 2026 |