Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

55639
Total
4397
Critical
16518
High
16189
Medium
CVE ID Severity Score Description Published
CVE-2026-94626 HIGH 7.5 vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary … Sep 21, 2026
CVE-2026-94625 MEDIUM 5.3 vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can send … Sep 21, 2026
CVE-2026-94624 HIGH 7.5 vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers … Sep 21, 2026
CVE-2026-94623 HIGH 7.5 vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt … Sep 21, 2026
CVE-2026-94622 HIGH 7.5 vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. Attackers can send requests with … Sep 21, 2026
CVE-2026-94540 HIGH 7.7 DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity … Sep 21, 2026
CVE-2026-94536 MEDIUM 4.3 lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing authenticated users to read any employee's roles and permissions. Attackers can … Sep 21, 2026
CVE-2026-94535 HIGH 7.1 lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications. Attackers can call the … Sep 21, 2026
CVE-2026-94534 HIGH 7.1 lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify arbitrary user profiles. Attackers can … Sep 21, 2026
CVE-2026-94533 MEDIUM 6.5 lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated users to download arbitrary attachments. Attackers can retrieve other users' stored files … Sep 21, 2026
CVE-2026-94532 MEDIUM 6.5 lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user's full profile. Attackers can … Sep 21, 2026
CVE-2026-93340 MEDIUM 6.8 Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account … Sep 21, 2026
CVE-2026-88756 UNKNOWN — Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array submitted to the public login endpoint (POST /user/authenticate). Sep 21, 2026
CVE-2026-88738 HIGH 8.8 Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An authenticated attacker can upload a server-side … Sep 21, 2026
CVE-2026-79079 HIGH 7.8 An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components Sep 21, 2026
CVE-2026-78847 CRITICAL 9.8 An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to parse front matter when language is js/javascript.This … Sep 21, 2026
CVE-2026-78806 UNKNOWN — An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in … Sep 21, 2026
CVE-2026-65980 UNKNOWN — Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.3, Chartbrew's … Sep 21, 2026
CVE-2026-61852 UNKNOWN — Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's … Sep 21, 2026
CVE-2026-61851 UNKNOWN — Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's … Sep 21, 2026
CVE-2026-61743 MEDIUM 6.3 Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's … Sep 21, 2026
CVE-2026-61652 UNKNOWN — Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion. The issue affects all callers who streamed … Sep 21, 2026
CVE-2026-61541 UNKNOWN — Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests content from an untrusted server, or … Sep 21, 2026
CVE-2026-59830 MEDIUM 5.4 Discourse is an open-source discussion platform. Prior to 2026.7.0, the post action component failed to escape user-controlled display names before interpolating them into an HTML … Sep 21, 2026
CVE-2026-59815 MEDIUM 4.3 Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's ItemModel.checkIfAllowed() authorizes writes to … Sep 21, 2026