Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50855
Total
4075
Critical
15116
High
14809
Medium
CVE ID Severity Score Description Published
CVE-2026-15077 MEDIUM 4.3 GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have … Jul 29, 2026
CVE-2026-14351 MEDIUM 4.3 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain … Jul 29, 2026
CVE-2026-14341 MEDIUM 4.9 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain … Jul 29, 2026
CVE-2026-13268 HIGH 7.8 G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G … Jul 29, 2026
CVE-2026-13113 MEDIUM 6.5 GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain … Jul 29, 2026
CVE-2026-12436 HIGH 8.4 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain … Jul 29, 2026
CVE-2026-12357 HIGH 7.2 Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall … Jul 29, 2026
CVE-2025-14562 LOW 3.1 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain … Jul 29, 2026
CVE-2026-67429 CRITICAL 10.0 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config … Jul 29, 2026
CVE-2026-67428 HIGH 8.5 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_party/developer/http/requests.py, core.api.http_get, core.api.http_post, graphql.query, graphql.mutation, monitor.http_check, communication.slack_send, notification.discord.send_message, … Jul 29, 2026
CVE-2026-67427 HIGH 8.6 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable resolver expands ${env.VAR} for any host environment … Jul 29, 2026
CVE-2026-67426 CRITICAL 9.3 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/verification_service.py exposes unauthenticated POST /run on … Jul 29, 2026
CVE-2026-67425 HIGH 8.6 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the … Jul 29, 2026
CVE-2026-67424 HIGH 8.5 Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, http.request, and http.batch in src/core/modules/atomic/http/get.py, src/core/modules/atomic/http/request.py, and … Jul 29, 2026
CVE-2026-67201 HIGH 8.6 V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host-based allowlists by exploiting a … Jul 29, 2026
CVE-2026-66737 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Jul 29, 2026
CVE-2026-62995 UNKNOWN — joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. in versions 1.7.1 and prior, joserfc accepts … Jul 29, 2026
CVE-2026-59898 UNKNOWN — Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSocket upgrade via the lax V07 (or … Jul 29, 2026
CVE-2026-2482 LOW 3.1 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized … Jul 29, 2026
CVE-2026-16328 HIGH 8.6 In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's … Jul 29, 2026
CVE-2026-16326 CRITICAL 10.0 In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to … Jul 29, 2026
CVE-2026-14529 CRITICAL 9.4 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) … Jul 29, 2026
CVE-2026-13346 UNKNOWN — pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This … Jul 29, 2026
CVE-2026-12935 UNKNOWN — The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based buffer overflow. The issue occurs when … Jul 29, 2026
CVE-2026-10684 LOW 3.0 In subsys/debug/coredump/coredump_shell.c, print_coredump_hdr() used the 16-bit tgt_code field of a stored Zephyr coredump header directly as an index into coredump_target_code2str[], a fixed 7-element array of … Jul 29, 2026