Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49853
Total
4028
Critical
14819
High
14575
Medium
CVE ID Severity Score Description Published
CVE-2026-69255 UNKNOWN Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled … Aug 04, 2026
CVE-2026-64634 UNKNOWN A vulnerability allowing local privilege escalation to the Reporter service context. Aug 04, 2026
CVE-2026-64633 UNKNOWN A vulnerability allowing remote unauthenticated code execution on the agent host. Aug 04, 2026
CVE-2026-64631 UNKNOWN A vulnerability allowing a low-privileged user to inject SQL and extract database contents. Aug 04, 2026
CVE-2026-64630 UNKNOWN A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link. Aug 04, 2026
CVE-2026-63456 CRITICAL 9.8 Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access … Aug 04, 2026
CVE-2026-63455 CRITICAL 9.8 Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access … Aug 04, 2026
CVE-2026-58075 UNKNOWN A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally. Aug 04, 2026
CVE-2026-58074 UNKNOWN A vulnerability allowing a high-privileged user to execute arbitrary code on the server. Aug 04, 2026
CVE-2026-58073 UNKNOWN A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials. Aug 04, 2026
CVE-2026-58072 UNKNOWN A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution. Aug 04, 2026
CVE-2026-58071 UNKNOWN A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an … Aug 04, 2026
CVE-2026-58067 UNKNOWN A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service. Aug 04, 2026
CVE-2026-56848 HIGH 7.5 A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, … Aug 04, 2026
CVE-2026-48121 MEDIUM 6.7 @langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and below are vulnerable to NoSQL injection: checkpoint identifiers (thread_id, checkpoint_ns, checkpoint_id) … Aug 04, 2026
CVE-2026-18787 HIGH 8.8 A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the component RPC … Aug 04, 2026
CVE-2026-18785 MEDIUM 5.3 A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a manipulation can lead to use after … Aug 04, 2026
CVE-2026-18784 MEDIUM 5.3 A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute of the file src/client/ua_client_highlevel.c. Performing a manipulation results in … Aug 04, 2026
CVE-2026-18775 MEDIUM 6.3 A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/browser_tool.py of the component Browser … Aug 04, 2026
CVE-2026-18774 MEDIUM 6.3 A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image … Aug 04, 2026
CVE-2026-15920 MEDIUM 6.1 An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating … Aug 04, 2026
CVE-2026-15830 MEDIUM 5.3 An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested … Aug 04, 2026
CVE-2026-15337 MEDIUM 5.3 An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, … Aug 04, 2026
CVE-2026-15314 UNKNOWN Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation … Aug 04, 2026
CVE-2026-15307 HIGH 8.8 An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by … Aug 04, 2026