Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55639
Total
4397
Critical
16518
High
16189
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-94626 | HIGH | 7.5 | vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary … | Sep 21, 2026 |
| CVE-2026-94625 | MEDIUM | 5.3 | vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can send … | Sep 21, 2026 |
| CVE-2026-94624 | HIGH | 7.5 | vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers … | Sep 21, 2026 |
| CVE-2026-94623 | HIGH | 7.5 | vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt … | Sep 21, 2026 |
| CVE-2026-94622 | HIGH | 7.5 | vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. Attackers can send requests with … | Sep 21, 2026 |
| CVE-2026-94540 | HIGH | 7.7 | DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity … | Sep 21, 2026 |
| CVE-2026-94536 | MEDIUM | 4.3 | lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing authenticated users to read any employee's roles and permissions. Attackers can … | Sep 21, 2026 |
| CVE-2026-94535 | HIGH | 7.1 | lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications. Attackers can call the … | Sep 21, 2026 |
| CVE-2026-94534 | HIGH | 7.1 | lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify arbitrary user profiles. Attackers can … | Sep 21, 2026 |
| CVE-2026-94533 | MEDIUM | 6.5 | lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated users to download arbitrary attachments. Attackers can retrieve other users' stored files … | Sep 21, 2026 |
| CVE-2026-94532 | MEDIUM | 6.5 | lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user's full profile. Attackers can … | Sep 21, 2026 |
| CVE-2026-93340 | MEDIUM | 6.8 | Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account … | Sep 21, 2026 |
| CVE-2026-88756 | UNKNOWN | — | Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array submitted to the public login endpoint (POST /user/authenticate). | Sep 21, 2026 |
| CVE-2026-88738 | HIGH | 8.8 | Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An authenticated attacker can upload a server-side … | Sep 21, 2026 |
| CVE-2026-79079 | HIGH | 7.8 | An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components | Sep 21, 2026 |
| CVE-2026-78847 | CRITICAL | 9.8 | An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to parse front matter when language is js/javascript.This … | Sep 21, 2026 |
| CVE-2026-78806 | UNKNOWN | — | An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in … | Sep 21, 2026 |
| CVE-2026-65980 | UNKNOWN | — | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.3, Chartbrew's … | Sep 21, 2026 |
| CVE-2026-61852 | UNKNOWN | — | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's … | Sep 21, 2026 |
| CVE-2026-61851 | UNKNOWN | — | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's … | Sep 21, 2026 |
| CVE-2026-61743 | MEDIUM | 6.3 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's … | Sep 21, 2026 |
| CVE-2026-61652 | UNKNOWN | — | Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion. The issue affects all callers who streamed … | Sep 21, 2026 |
| CVE-2026-61541 | UNKNOWN | — | Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests content from an untrusted server, or … | Sep 21, 2026 |
| CVE-2026-59830 | MEDIUM | 5.4 | Discourse is an open-source discussion platform. Prior to 2026.7.0, the post action component failed to escape user-controlled display names before interpolating them into an HTML … | Sep 21, 2026 |
| CVE-2026-59815 | MEDIUM | 4.3 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's ItemModel.checkIfAllowed() authorizes writes to … | Sep 21, 2026 |