Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54704
Total
4321
Critical
16261
High
15994
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-97232 | MEDIUM | 6.3 | A vulnerability was determined in volotat Anagnorisis up to 0.4.2. Affected by this vulnerability is the function get_file_content/save_file_content/move_files/start_streaming of the file page.html. This manipulation causes … | Sep 24, 2026 |
| CVE-2026-95985 | HIGH | 8.8 | The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When … | Sep 24, 2026 |
| CVE-2026-93405 | MEDIUM | 6.1 | Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markdown, DOCX, and XLSX attachments with Snarkdown, Mammoth, and SheetJS … | Sep 24, 2026 |
| CVE-2026-91121 | MEDIUM | 5.0 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, attacker-controlled upload filenames used in chat message excerpts were rendered as unescaped … | Sep 24, 2026 |
| CVE-2026-91120 | MEDIUM | 5.4 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, provider-controlled video titles in lazy video embeds could be reparsed as HTML … | Sep 24, 2026 |
| CVE-2026-91119 | MEDIUM | 6.4 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the topic small-action and nested-activity-log components interpolated the free-form action_code_who value into … | Sep 24, 2026 |
| CVE-2026-85057 | HIGH | 8.7 | ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables the goja Node-compatible require() registry without restricting … | Sep 24, 2026 |
| CVE-2026-85056 | HIGH | 8.2 | ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1, ZITADEL Login V2 creates a browser session after password verification and can reuse … | Sep 24, 2026 |
| CVE-2026-81508 | MEDIUM | 4.3 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.5, 6.0.1, and 6.1, the BlueDroid A2DP sink function btc_a2dp_sink_handle_inc_media() reads a timestamp field … | Sep 24, 2026 |
| CVE-2026-71540 | HIGH | 7.5 | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.9.0 until 4.14.7, wazuh-clusterd in framework/wazuh/core/cluster/common.py allocates … | Sep 24, 2026 |
| CVE-2026-63645 | HIGH | 7.5 | OpenObserve is a cloud-native observability platform. Prior to 0.90.3, OpenObserve registers the /config/runtime endpoint without authentication and serializes the complete server configuration after applying the … | Sep 24, 2026 |
| CVE-2026-61816 | HIGH | 7.5 | zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Starting in … | Sep 24, 2026 |
| CVE-2026-61815 | HIGH | 7.2 | zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Prior to … | Sep 24, 2026 |
| CVE-2026-61811 | MEDIUM | 6.5 | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.8.0 until 4.14.7, the _getattributes() function in … | Sep 24, 2026 |
| CVE-2026-61788 | HIGH | 7.4 | DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Prior to version 0.22.6, setting `readonly = true` on the `execute_sql` … | Sep 24, 2026 |
| CVE-2026-61784 | MEDIUM | 6.1 | xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, trusted HTML. Versions prior to 0.4.3 do not HTML-entity-encode attribute values … | Sep 24, 2026 |
| CVE-2026-61782 | HIGH | 7.5 | Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to version 1.5.16, the default Rsdoctor report HTTP server started by `@rsdoctor/rspack-plugin` binds … | Sep 24, 2026 |
| CVE-2026-61742 | UNKNOWN | — | DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose an unauthenticated HTTP MCP endpoint when … | Sep 24, 2026 |
| CVE-2026-61741 | CRITICAL | 9.3 | http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` without … | Sep 24, 2026 |
| CVE-2026-61732 | CRITICAL | 10.0 | Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of agent reconnaissance against target … | Sep 24, 2026 |
| CVE-2026-61604 | UNKNOWN | — | The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds module moved funds from … | Sep 24, 2026 |
| CVE-2026-57179 | MEDIUM | 4.2 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it … | Sep 24, 2026 |
| CVE-2026-57178 | HIGH | 7.4 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature … | Sep 24, 2026 |
| CVE-2026-57177 | MEDIUM | 4.3 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications … | Sep 24, 2026 |
| CVE-2026-57176 | MEDIUM | 6.8 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth … | Sep 24, 2026 |