Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50663
Total
4071
Critical
15059
High
14768
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-5056 | HIGH | 7.8 | GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with … | Jul 29, 2026 |
| CVE-2026-4672 | MEDIUM | 4.3 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain … | Jul 29, 2026 |
| CVE-2026-3093 | MEDIUM | 4.7 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain … | Jul 29, 2026 |
| CVE-2026-18266 | MEDIUM | 5.4 | Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dify. User interaction is required … | Jul 29, 2026 |
| CVE-2026-18022 | HIGH | 8.8 | Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. … | Jul 29, 2026 |
| CVE-2026-16553 | MEDIUM | 5.4 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain … | Jul 29, 2026 |
| CVE-2026-15975 | HIGH | 7.5 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain … | Jul 29, 2026 |
| CVE-2026-15831 | MEDIUM | 4.3 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have … | Jul 29, 2026 |
| CVE-2026-15077 | MEDIUM | 4.3 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have … | Jul 29, 2026 |
| CVE-2026-14351 | MEDIUM | 4.3 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain … | Jul 29, 2026 |
| CVE-2026-14341 | MEDIUM | 4.9 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain … | Jul 29, 2026 |
| CVE-2026-13268 | HIGH | 7.8 | G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G … | Jul 29, 2026 |
| CVE-2026-13113 | MEDIUM | 6.5 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain … | Jul 29, 2026 |
| CVE-2026-12436 | HIGH | 8.4 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain … | Jul 29, 2026 |
| CVE-2026-12357 | HIGH | 7.2 | Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall … | Jul 29, 2026 |
| CVE-2025-14562 | LOW | 3.1 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain … | Jul 29, 2026 |
| CVE-2026-67429 | CRITICAL | 10.0 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config … | Jul 29, 2026 |
| CVE-2026-67428 | HIGH | 8.5 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_party/developer/http/requests.py, core.api.http_get, core.api.http_post, graphql.query, graphql.mutation, monitor.http_check, communication.slack_send, notification.discord.send_message, … | Jul 29, 2026 |
| CVE-2026-67427 | HIGH | 8.6 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable resolver expands ${env.VAR} for any host environment … | Jul 29, 2026 |
| CVE-2026-67426 | CRITICAL | 9.3 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/verification_service.py exposes unauthenticated POST /run on … | Jul 29, 2026 |
| CVE-2026-67425 | HIGH | 8.6 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the … | Jul 29, 2026 |
| CVE-2026-67424 | HIGH | 8.5 | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, http.request, and http.batch in src/core/modules/atomic/http/get.py, src/core/modules/atomic/http/request.py, and … | Jul 29, 2026 |
| CVE-2026-67201 | HIGH | 8.6 | V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host-based allowlists by exploiting a … | Jul 29, 2026 |
| CVE-2026-66737 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Jul 29, 2026 |
| CVE-2026-62995 | UNKNOWN | — | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. in versions 1.7.1 and prior, joserfc accepts … | Jul 29, 2026 |