Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

30264
Total
2400
Critical
9076
High
9418
Medium
CVE ID Severity Score Description Published
CVE-2026-35405 HIGH 7.5 libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, libp2p-rendezvous server has no limit on how many namespaces a … Apr 07, 2026
CVE-2026-33034 HIGH 7.5 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could … Apr 07, 2026
CVE-2026-33033 MEDIUM 6.5 An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote attackers to degrade performance by submitting multipart … Apr 07, 2026
CVE-2026-30079 UNKNOWN In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration procedure. This allows authentication to be bypassed completely. If a … Apr 07, 2026
CVE-2026-24660 HIGH 8.1 A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer … Apr 07, 2026
CVE-2026-24450 HIGH 8.1 An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. … Apr 07, 2026
CVE-2026-21413 CRITICAL 9.8 A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to … Apr 07, 2026
CVE-2026-20911 CRITICAL 9.8 A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and Commit d20315b. A specially crafted malicious file can lead to … Apr 07, 2026
CVE-2026-20889 CRITICAL 9.8 A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b. A specially crafted malicious file can lead to a heap buffer … Apr 07, 2026
CVE-2026-20884 HIGH 8.1 An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially crafted malicious file can lead to a heap buffer overflow. … Apr 07, 2026
CVE-2025-62818 UNKNOWN An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, … Apr 07, 2026
CVE-2025-52909 UNKNOWN An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, … Apr 07, 2026
CVE-2026-5627 CRITICAL 9.1 A path traversal vulnerability exists in mintplex-labs/anything-llm versions up to and including 1.9.1, within the `AgentFlows` component. The vulnerability arises from improper handling of user … Apr 07, 2026
CVE-2026-35554 HIGH 8.7 A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. When a … Apr 07, 2026
CVE-2026-5735 CRITICAL 9.8 Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough … Apr 07, 2026
CVE-2026-5734 CRITICAL 9.8 Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption … Apr 07, 2026
CVE-2026-5733 HIGH 8.8 Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 149.0.2 and Thunderbird < 149.0.2. Apr 07, 2026
CVE-2026-5732 HIGH 8.8 Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability affects Firefox < 149.0.2, Firefox ESR < 140.9.1, Thunderbird < 149.0.2, and Thunderbird … Apr 07, 2026
CVE-2026-5731 CRITICAL 9.8 Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence … Apr 07, 2026
CVE-2026-3466 UNKNOWN Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 … Apr 07, 2026
CVE-2026-33866 UNKNOWN MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due to missing access‑control validation, a user without … Apr 07, 2026
CVE-2026-33865 UNKNOWN MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface. An authenticated attacker can upload … Apr 07, 2026
CVE-2026-32144 UNKNOWN Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via missing signature verification. The OCSP response validation in public_key:pkix_ocsp_validate/5 … Apr 07, 2026
CVE-2026-28808 UNKNOWN Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps … Apr 07, 2026
CVE-2026-23818 HIGH 8.8 A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to … Apr 07, 2026