Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

30355
Total
2427
Critical
9086
High
9450
Medium
CVE ID Severity Score Description Published
CVE-2026-42042 MEDIUM 5.4 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token protection logic uses … Apr 24, 2026
CVE-2026-42041 MEDIUM 4.8 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype … Apr 24, 2026
CVE-2026-42040 LOW 3.7 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the encode() function in lib/helpers/AxiosURLSearchParams.js contains a character … Apr 24, 2026
CVE-2026-42039 UNKNOWN Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth … Apr 24, 2026
CVE-2026-42038 MEDIUM 6.8 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostname normalization bypass is … Apr 24, 2026
CVE-2026-42037 MEDIUM 5.3 Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart constructor in lib/helpers/formDataToStream.js interpolates value.type directly … Apr 24, 2026
CVE-2026-42036 MEDIUM 5.3 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns the … Apr 24, 2026
CVE-2026-42035 HIGH 7.4 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios … Apr 24, 2026
CVE-2026-42034 MEDIUM 5.3 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed when … Apr 24, 2026
CVE-2026-42033 HIGH 7.4 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency … Apr 24, 2026
CVE-2026-41898 UNKNOWN rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callback, set_cookie_generate_cb, and set_stateless_cookie_generate_cb forwarded the … Apr 24, 2026
CVE-2026-41681 UNKNOWN rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is … Apr 24, 2026
CVE-2026-41680 UNKNOWN Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a specific … Apr 24, 2026
CVE-2026-41678 UNKNOWN rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= … Apr 24, 2026
CVE-2026-41677 UNKNOWN rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the … Apr 24, 2026
CVE-2026-41676 UNKNOWN rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as … Apr 24, 2026
CVE-2026-41322 MEDIUM 5.3 @astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a static js/css resources from _astro path with an incorrect/malformed … Apr 24, 2026
CVE-2026-41321 LOW 2.2 @astrojs/cloudflare is an SSR adapter for use with Cloudflare Workers targets. Prior to 13.1.10, the fetch() call for remote images in packages/integrations/cloudflare/src/utils/image-binding-transform.ts uses the default … Apr 24, 2026
CVE-2026-41140 UNKNOWN Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist tarballs without path traversal protection on Python versions … Apr 24, 2026
CVE-2026-6912 HIGH 8.8 Improperly controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration in AWS Ops Wheel before PR #165 allows remote authenticated users to … Apr 24, 2026
CVE-2026-6911 CRITICAL 9.8 Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain unintended administrative access to the application, including the … Apr 24, 2026
CVE-2026-41411 MEDIUM 6.6 Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a … Apr 24, 2026
CVE-2026-41079 MEDIUM 4.3 OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted … Apr 24, 2026
CVE-2026-41067 MEDIUM 6.1 Astro is a web framework. Prior to 6.1.6, the defineScriptVars function in Astro's server-side rendering pipeline uses a case-sensitive regex /<\/script>/g to sanitize values injected … Apr 24, 2026
CVE-2026-41066 HIGH 7.5 lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default … Apr 24, 2026