Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50855
Total
4075
Critical
15116
High
14809
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-66063 | MEDIUM | 6.5 | goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown.go multipart upload handler split part.FileName() on / but … | Jul 28, 2026 |
| CVE-2026-64863 | CRITICAL | 9.1 | goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method … | Jul 28, 2026 |
| CVE-2026-62325 | CRITICAL | 9.1 | goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && … | Jul 28, 2026 |
| CVE-2026-59921 | MEDIUM | 5.7 | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames … | Jul 28, 2026 |
| CVE-2026-54719 | HIGH | 7.5 | goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not … | Jul 28, 2026 |
| CVE-2026-54659 | UNKNOWN | — | Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values verbatim and later used them as <locale>.yml path … | Jul 28, 2026 |
| CVE-2026-54658 | CRITICAL | 9.8 | Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing … | Jul 28, 2026 |
| CVE-2026-54650 | HIGH | 8.6 | openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target … | Jul 28, 2026 |
| CVE-2026-54638 | HIGH | 7.5 | gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted … | Jul 28, 2026 |
| CVE-2026-47219 | HIGH | 7.5 | find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wildcards. Versions prior to 9.7.0 are vulnerable to … | Jul 28, 2026 |
| CVE-2026-55415 | HIGH | 7.5 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.11.6 until … | Jul 28, 2026 |
| CVE-2026-55403 | LOW | 3.7 | datamodel-code-generator generates Python data models from schema definitions. Prior to 0.63.0, src/datamodel_code_generator/http.py get_body reuses Authorization, Cookie, and Proxy-Authorization headers when following cross-origin redirects while fetching … | Jul 28, 2026 |
| CVE-2026-55391 | HIGH | 7.5 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.63.0, … | Jul 28, 2026 |
| CVE-2026-55390 | HIGH | 7.5 | datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for --input-file-type xmlschema resolves xs:include, xs:import, xs:redefine, and … | Jul 28, 2026 |
| CVE-2026-55389 | HIGH | 7.5 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.62.0, … | Jul 28, 2026 |
| CVE-2026-54691 | HIGH | 8.2 | datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get_body accepts --url targets and redirect chain targets without host/IP validation, allowing … | Jul 28, 2026 |
| CVE-2026-54690 | HIGH | 8.2 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.9.1 until … | Jul 28, 2026 |
| CVE-2026-54656 | HIGH | 7.8 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.52.1 until … | Jul 28, 2026 |
| CVE-2026-54655 | HIGH | 7.8 | datamodel-code-generator generates Python data models from schema definitions. From 0.51.0 until 0.60.2, x-python-type values parsed by src/datamodel_code_generator/parser/jsonschema.py in _get_python_type_override are inserted into generated field annotations … | Jul 28, 2026 |
| CVE-2026-54654 | HIGH | 7.8 | datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the --extra-template-data comment field is rendered into Python comments in src/datamodel_code_generator/model/template/TypeAliasAnnotation.jinja2, src/datamodel_code_generator/model/template/TypedDict.jinja2, src/datamodel_code_generator/model/template/dataclass.jinja2, … | Jul 28, 2026 |
| CVE-2026-54653 | HIGH | 8.8 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.17.0 until … | Jul 28, 2026 |
| CVE-2026-54621 | HIGH | 7.8 | datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union description values in src/datamodel_code_generator/model/template/UnionTypeStatement.jinja2 and src/datamodel_code_generator/model/template/UnionTypeStatement.py312.jinja2 are rendered into Python comments without … | Jul 28, 2026 |
| CVE-2026-6881 | UNKNOWN | — | A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases … | Jul 28, 2026 |
| CVE-2026-59943 | UNKNOWN | — | Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by … | Jul 28, 2026 |
| CVE-2026-59942 | UNKNOWN | — | Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. … | Jul 28, 2026 |