Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49853
Total
4028
Critical
14819
High
14575
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-29296 | CRITICAL | 9.8 | H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C … | Aug 04, 2026 |
| CVE-2026-69254 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-provided nodeVMOptions and merged … | Aug 04, 2026 |
| CVE-2026-69253 | UNKNOWN | — | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and … | Aug 04, 2026 |
| CVE-2026-69252 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only … | Aug 04, 2026 |
| CVE-2026-69110 | CRITICAL | 9.1 | OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by … | Aug 04, 2026 |
| CVE-2026-69100 | HIGH | 8.8 | LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database … | Aug 04, 2026 |
| CVE-2026-69098 | CRITICAL | 9.8 | kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON … | Aug 04, 2026 |
| CVE-2026-25292 | HIGH | 7.6 | Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration. | Aug 04, 2026 |
| CVE-2026-25289 | CRITICAL | 9.6 | Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values. | Aug 04, 2026 |
| CVE-2026-25288 | HIGH | 7.4 | Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size. | Aug 04, 2026 |
| CVE-2026-24084 | HIGH | 7.5 | Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities. | Aug 04, 2026 |
| CVE-2026-24083 | HIGH | 7.8 | Memory Corruption while processing IOCTL device driver requests with invalid arguments. | Aug 04, 2026 |
| CVE-2026-24080 | HIGH | 7.8 | Memory Corruption when handling malformed request parameters in the fingerprint TA. | Aug 04, 2026 |
| CVE-2026-24079 | HIGH | 8.1 | Cryptographic Issue while processing registration requests with malformed or missing authentication parameters. | Aug 04, 2026 |
| CVE-2026-24078 | MEDIUM | 6.5 | Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. | Aug 04, 2026 |
| CVE-2026-24077 | MEDIUM | 6.5 | Information Disclosure when processing wireless network channel switch information with improperly formatted length fields. | Aug 04, 2026 |
| CVE-2026-24076 | MEDIUM | 6.7 | Memory Corruption when processing registry values with incorrect types using a direct query method. | Aug 04, 2026 |
| CVE-2026-21366 | HIGH | 7.8 | Memory corruption while processing a packet with a size close to the maximum allowed value. | Aug 04, 2026 |
| CVE-2026-18801 | UNKNOWN | — | OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution values. An attacker who can create or update a customer … | Aug 04, 2026 |
| CVE-2026-18773 | MEDIUM | 6.3 | A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component … | Aug 04, 2026 |
| CVE-2026-10032 | UNKNOWN | — | The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the URI scheme. A malicious agent can supply a javascript: URI … | Aug 04, 2026 |
| CVE-2026-69251 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory … | Aug 04, 2026 |
| CVE-2026-69250 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST … | Aug 04, 2026 |
| CVE-2026-68494 | UNKNOWN | — | The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint bypass in the non-blocking parser) is incomplete. This record covers the … | Aug 04, 2026 |
| CVE-2026-67618 | MEDIUM | 6.5 | marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operator API keys by embedding a malicious base_url in PEP-723 inline … | Aug 04, 2026 |