Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54155
Total
4297
Critical
16098
High
15777
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-104874 | MEDIUM | 5.3 | Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl … | Oct 02, 2026 |
| CVE-2026-104055 | UNKNOWN | — | The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the … | Oct 02, 2026 |
| CVE-2026-82040 | MEDIUM | 5.0 | UTMStack before 11.2.16 contains a server-side request forgery vulnerability in IdentityProviderService.validateMetadataUrl() that allows authenticated attackers to make the server send requests to arbitrary internal or … | Oct 02, 2026 |
| CVE-2026-82039 | HIGH | 8.8 | UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values … | Oct 02, 2026 |
| CVE-2026-39718 | HIGH | 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet allows Cross Site Request Forgery.This issue affects Wallstreet: from n/a through 2.8.6. | Oct 02, 2026 |
| CVE-2026-12392 | MEDIUM | 5.3 | An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret … | Oct 02, 2026 |
| CVE-2026-104994 | LOW | 2.5 | Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using … | Oct 02, 2026 |
| CVE-2026-104991 | HIGH | 7.1 | Phproject before 1.8.7 contains a missing object-level authorization vulnerability in the REST API issue endpoints (single_get, single_comments, single_comments_post) that allows authenticated API key holders to … | Oct 02, 2026 |
| CVE-2026-104988 | HIGH | 8.1 | A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without … | Oct 02, 2026 |
| CVE-2026-104873 | UNKNOWN | — | LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. From 0.1.45 until 0.4.4, … | Oct 02, 2026 |
| CVE-2026-104872 | MEDIUM | 5.8 | OpenTelemetry JavaScript Contrib provides instrumentation libraries for collecting telemetry from JavaScript applications. Prior to versions 0.66.0 of @opentelemetry/instrumentation-cassandra-driver, 0.65.0 of @opentelemetry/instrumentation-knex, 0.67.0 of @opentelemetry/instrumentation-mongoose, @opentelemetry/instrumentation-mysql, … | Oct 02, 2026 |
| CVE-2026-104871 | UNKNOWN | — | The Angular SSR is a server-rise rendering tool for Angular applications. Prior to versions 20.3.36, 21.2.23, and 22.1.7, the CommonEngine retrieveSSGPage prerendered-page retrieval logic in … | Oct 02, 2026 |
| CVE-2026-104019 | CRITICAL | 9.0 | OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before … | Oct 02, 2026 |
| CVE-2026-103918 | MEDIUM | 6.5 | oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.10, the @orpc/zod ZodSmartCoercionPlugin and experimental_ZodSmartCoercionPlugin … | Oct 02, 2026 |
| CVE-2026-103036 | MEDIUM | 6.5 | oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.9, the @orpc/json-schema SmartCoercionPlugin uses JsonSchemaCoercer … | Oct 02, 2026 |
| CVE-2026-96940 | HIGH | 8.8 | Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. | Oct 02, 2026 |
| CVE-2026-19856 | MEDIUM | 6.5 | The All in One SEO WordPress plugin before 5.0.2.1 does not correctly determine which shortcodes are present in content derived from user input before deciding … | Oct 02, 2026 |
| CVE-2026-103958 | HIGH | 7.6 | Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to … | Oct 02, 2026 |
| CVE-2026-103957 | MEDIUM | 6.2 | Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the access token … | Oct 02, 2026 |
| CVE-2026-103956 | CRITICAL | 10.0 | Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent … | Oct 02, 2026 |
| CVE-2023-54405 | CRITICAL | 9.8 | H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that … | Oct 02, 2026 |
| CVE-2020-37278 | HIGH | 7.5 | Weaver e-Bridge contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to access arbitrary files on the host system by supplying a file: … | Oct 02, 2026 |
| CVE-2014-125130 | HIGH | 7.5 | CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive … | Oct 02, 2026 |
| CVE-2026-64818 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Oct 02, 2026 |
| CVE-2026-59265 | UNKNOWN | — | A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) … | Oct 02, 2026 |