Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50089
Total
4047
Critical
14897
High
14637
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-48121 | MEDIUM | 6.7 | @langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and below are vulnerable to NoSQL injection: checkpoint identifiers (thread_id, checkpoint_ns, checkpoint_id) … | Aug 04, 2026 |
| CVE-2026-18787 | HIGH | 8.8 | A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the component RPC … | Aug 04, 2026 |
| CVE-2026-18785 | MEDIUM | 5.3 | A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a manipulation can lead to use after … | Aug 04, 2026 |
| CVE-2026-18784 | MEDIUM | 5.3 | A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute of the file src/client/ua_client_highlevel.c. Performing a manipulation results in … | Aug 04, 2026 |
| CVE-2026-18775 | MEDIUM | 6.3 | A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/browser_tool.py of the component Browser … | Aug 04, 2026 |
| CVE-2026-18774 | MEDIUM | 6.3 | A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image … | Aug 04, 2026 |
| CVE-2026-15920 | MEDIUM | 6.1 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating … | Aug 04, 2026 |
| CVE-2026-15830 | MEDIUM | 5.3 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested … | Aug 04, 2026 |
| CVE-2026-15337 | MEDIUM | 5.3 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, … | Aug 04, 2026 |
| CVE-2026-15314 | UNKNOWN | — | Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation … | Aug 04, 2026 |
| CVE-2026-15307 | HIGH | 8.8 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by … | Aug 04, 2026 |
| CVE-2025-29296 | CRITICAL | 9.8 | H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C … | Aug 04, 2026 |
| CVE-2026-69254 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-provided nodeVMOptions and merged … | Aug 04, 2026 |
| CVE-2026-69253 | UNKNOWN | — | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and … | Aug 04, 2026 |
| CVE-2026-69252 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only … | Aug 04, 2026 |
| CVE-2026-69110 | CRITICAL | 9.1 | OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by … | Aug 04, 2026 |
| CVE-2026-69100 | HIGH | 8.8 | LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database … | Aug 04, 2026 |
| CVE-2026-69098 | CRITICAL | 9.8 | kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON … | Aug 04, 2026 |
| CVE-2026-25292 | HIGH | 7.6 | Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration. | Aug 04, 2026 |
| CVE-2026-25289 | CRITICAL | 9.6 | Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values. | Aug 04, 2026 |
| CVE-2026-25288 | HIGH | 7.4 | Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size. | Aug 04, 2026 |
| CVE-2026-24084 | HIGH | 7.5 | Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities. | Aug 04, 2026 |
| CVE-2026-24083 | HIGH | 7.8 | Memory Corruption while processing IOCTL device driver requests with invalid arguments. | Aug 04, 2026 |
| CVE-2026-24080 | HIGH | 7.8 | Memory Corruption when handling malformed request parameters in the fingerprint TA. | Aug 04, 2026 |
| CVE-2026-24079 | HIGH | 8.1 | Cryptographic Issue while processing registration requests with malformed or missing authentication parameters. | Aug 04, 2026 |