Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
34320
Total
2676
Critical
10130
High
10349
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-43667 | UNKNOWN | — | A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An attacker in a privileged network … | Aug 17, 2026 |
| CVE-2026-42163 | UNKNOWN | — | Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI … | Aug 17, 2026 |
| CVE-2026-28984 | UNKNOWN | — | The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. Processing maliciously crafted web content may lead … | Aug 17, 2026 |
| CVE-2026-11817 | UNKNOWN | — | This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org … | Aug 17, 2026 |
| CVE-2026-10080 | MEDIUM | 6.5 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSocket command field types which allows an authenticated user to crash … | Aug 17, 2026 |
| CVE-2026-75531 | UNKNOWN | — | Pandora contains a stored cross-site scripting (XSS) vulnerability in the rendering of URL observables. A URL extracted from or associated with an analyzed file was … | Aug 17, 2026 |
| CVE-2026-75529 | UNKNOWN | — | Pandora is affected by a stored cross-site scripting vulnerability in the PDF download functionality. The /task-download/<task_id>/.../pdf endpoint verifies that the submitted file is a PDF … | Aug 17, 2026 |
| CVE-2026-75483 | LOW | 3.3 | powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt segment. Attackers can inject raw escape bytes in the … | Aug 17, 2026 |
| CVE-2026-75482 | HIGH | 7.5 | SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in its /trajectory/ handler without … | Aug 17, 2026 |
| CVE-2026-75481 | HIGH | 8.8 | SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers can create a service account, escalate … | Aug 17, 2026 |
| CVE-2026-75480 | MEDIUM | 6.5 | OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users to read all co-tenant records. Attackers can … | Aug 17, 2026 |
| CVE-2026-75479 | HIGH | 7.5 | JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. … | Aug 17, 2026 |
| CVE-2026-75111 | HIGH | 7.5 | Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read arbitrary files outside the workspace directory. … | Aug 17, 2026 |
| CVE-2026-75110 | CRITICAL | 9.8 | MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment variable … | Aug 17, 2026 |
| CVE-2026-75109 | HIGH | 7.1 | Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authenticated attackers can disrupt other users' workloads … | Aug 17, 2026 |
| CVE-2026-75108 | MEDIUM | 5.4 | Next Terminal fails to enforce per-asset authorization checks on the portal ping and wake-on-LAN endpoints, allowing any authenticated user to probe and wake assets they … | Aug 17, 2026 |
| CVE-2026-75106 | CRITICAL | 9.1 | OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers … | Aug 17, 2026 |
| CVE-2026-75105 | HIGH | 7.5 | phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/index.php and … | Aug 17, 2026 |
| CVE-2026-75104 | MEDIUM | 5.5 | Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply … | Aug 17, 2026 |
| CVE-2026-75103 | HIGH | 8.8 | Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate … | Aug 17, 2026 |
| CVE-2026-73560 | MEDIUM | 6.5 | vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in vllm/transformers_utils/processors/mimo_v2_omni.py passes attacker-controlled image and audio strings through … | Aug 17, 2026 |
| CVE-2026-73410 | HIGH | 8.5 | Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outboundFetch.ts pinned a validated address through a Node agent, but the REST integration used getDispatcher from … | Aug 17, 2026 |
| CVE-2026-71518 | HIGH | 7.5 | Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent … | Aug 17, 2026 |
| CVE-2026-68765 | MEDIUM | 6.1 | hashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePass AESKDF/KDBX v4 module (module 34301) that allows attackers to corrupt … | Aug 17, 2026 |
| CVE-2026-67967 | UNKNOWN | — | Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-44867 and CVE-2026-36819 | Aug 17, 2026 |