Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50129
Total
4051
Critical
14904
High
14658
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-69244 | UNKNOWN | — | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser … | Aug 03, 2026 |
| CVE-2026-69243 | UNKNOWN | — | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating … | Aug 03, 2026 |
| CVE-2026-69240 | CRITICAL | 9.8 | Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function … | Aug 03, 2026 |
| CVE-2026-67976 | UNKNOWN | — | The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Denial of Service (DoS) via … | Aug 03, 2026 |
| CVE-2026-67972 | UNKNOWN | — | An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data is stored, possibly leading to an … | Aug 03, 2026 |
| CVE-2026-66065 | UNKNOWN | — | Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have … | Aug 03, 2026 |
| CVE-2026-52521 | UNKNOWN | — | A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the CommentBat feature. | Aug 03, 2026 |
| CVE-2026-52520 | UNKNOWN | — | Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/article.php). A remote authenticated attacker can inject arbitrary JavaScript … | Aug 03, 2026 |
| CVE-2026-52102 | UNKNOWN | — | An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters. | Aug 03, 2026 |
| CVE-2026-51775 | UNKNOWN | — | SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the application/common/controller/Backend.php component | Aug 03, 2026 |
| CVE-2026-51190 | UNKNOWN | — | The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spawn() with shell: true. A URL ending in ".git" bypasses the … | Aug 03, 2026 |
| CVE-2026-49132 | MEDIUM | 5.4 | OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScript by embedding payloads in the certificate … | Aug 03, 2026 |
| CVE-2026-49131 | MEDIUM | 5.4 | OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with firewall rule management privileges to inject arbitrary HTML or JavaScript by … | Aug 03, 2026 |
| CVE-2026-48113 | UNKNOWN | — | Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated clients can bypass --authfile ACL restrictions and … | Aug 03, 2026 |
| CVE-2026-48063 | UNKNOWN | — | Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious … | Aug 03, 2026 |
| CVE-2026-48061 | MEDIUM | 5.9 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the … | Aug 03, 2026 |
| CVE-2026-41447 | HIGH | 7.8 | FirmaCheck for Windows before 1.3.16 contains a dll hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in … | Aug 03, 2026 |
| CVE-2026-18738 | MEDIUM | 4.7 | Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote attackers to plant spreadsheet formulas into exported visit data by … | Aug 03, 2026 |
| CVE-2026-18737 | MEDIUM | 6.5 | Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL fragments by supplying an unvalidated direction value … | Aug 03, 2026 |
| CVE-2026-18736 | MEDIUM | 5.0 | Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying … | Aug 03, 2026 |
| CVE-2026-18733 | HIGH | 8.8 | A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands … | Aug 03, 2026 |
| CVE-2026-18648 | MEDIUM | 5.3 | A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the … | Aug 03, 2026 |
| CVE-2026-18647 | HIGH | 7.3 | A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue affects the function isValidTLD of the file /backend/functions/src/cloud-functions/crawler.ts of the component … | Aug 03, 2026 |
| CVE-2026-18646 | MEDIUM | 5.3 | A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system/htmly.php of the component Author Name … | Aug 03, 2026 |
| CVE-2026-18645 | MEDIUM | 5.4 | A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /system/admin/admin.php of the component Admin … | Aug 03, 2026 |