Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50089
Total
4047
Critical
14897
High
14637
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-24254 | CRITICAL | 9.8 | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this … | Aug 04, 2026 |
| CVE-2026-24253 | HIGH | 8.2 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial … | Aug 04, 2026 |
| CVE-2026-18830 | HIGH | 8.1 | Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via … | Aug 04, 2026 |
| CVE-2026-18790 | LOW | 3.3 | A weakness has been identified in Systerel S2OPC up to 1.7.3. This affects the function LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse of the file src/ClientServer/frontend/client_wrapper/internal/state_machine.c of the component DeleteMonitoredItemsRequest Handler. … | Aug 04, 2026 |
| CVE-2026-18788 | HIGH | 7.3 | A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager/dialog.php. The manipulation … | Aug 04, 2026 |
| CVE-2026-69263 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y … | Aug 04, 2026 |
| CVE-2026-69262 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), … | Aug 04, 2026 |
| CVE-2026-69259 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in … | Aug 04, 2026 |
| CVE-2026-69258 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted … | Aug 04, 2026 |
| CVE-2026-69257 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did … | Aug 04, 2026 |
| CVE-2026-69256 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to … | Aug 04, 2026 |
| CVE-2026-69255 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled … | Aug 04, 2026 |
| CVE-2026-64634 | UNKNOWN | — | A vulnerability allowing local privilege escalation to the Reporter service context. | Aug 04, 2026 |
| CVE-2026-64633 | UNKNOWN | — | A vulnerability allowing remote unauthenticated code execution on the agent host. | Aug 04, 2026 |
| CVE-2026-64631 | UNKNOWN | — | A vulnerability allowing a low-privileged user to inject SQL and extract database contents. | Aug 04, 2026 |
| CVE-2026-64630 | UNKNOWN | — | A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link. | Aug 04, 2026 |
| CVE-2026-63456 | CRITICAL | 9.8 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access … | Aug 04, 2026 |
| CVE-2026-63455 | CRITICAL | 9.8 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access … | Aug 04, 2026 |
| CVE-2026-58075 | UNKNOWN | — | A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally. | Aug 04, 2026 |
| CVE-2026-58074 | UNKNOWN | — | A vulnerability allowing a high-privileged user to execute arbitrary code on the server. | Aug 04, 2026 |
| CVE-2026-58073 | UNKNOWN | — | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials. | Aug 04, 2026 |
| CVE-2026-58072 | UNKNOWN | — | A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution. | Aug 04, 2026 |
| CVE-2026-58071 | UNKNOWN | — | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an … | Aug 04, 2026 |
| CVE-2026-58067 | UNKNOWN | — | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service. | Aug 04, 2026 |
| CVE-2026-56848 | HIGH | 7.5 | A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, … | Aug 04, 2026 |