Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56907
Total
4512
Critical
16897
High
16715
Medium
CVE ID Severity Score Description Published
CVE-2026-92217 MEDIUM 6.3 A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/message-processor.ts of the component Message Parsing. This … Sep 16, 2026
CVE-2026-92216 MEDIUM 4.3 A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component … Sep 16, 2026
CVE-2026-92215 HIGH 7.3 A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the function httpx.get of the file agent_sdks/python/a2ui_agent/src/a2ui/extensions/file_resolve/file_resolver.py of the … Sep 16, 2026
CVE-2026-92214 LOW 3.5 A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/client/angular/projects/a2a-chat-canvas/src/lib/services/sanitizer-markdown-renderer-service.ts of the component a2a-chat-canvas. Executing … Sep 16, 2026
CVE-2026-92213 MEDIUM 5.5 A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This impacts the function z.any of the file renderers/web_core/src/v0_9/schema/server-to-client.ts of the component Angular Renderer. Performing … Sep 16, 2026
CVE-2026-92184 MEDIUM 6.3 A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component Multimodal Content. The … Sep 16, 2026
CVE-2026-73460 MEDIUM 6.1 On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause … Sep 16, 2026
CVE-2026-73459 HIGH 7.4 On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate … Sep 16, 2026
CVE-2026-73446 HIGH 7.4 On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit … Sep 16, 2026
CVE-2026-15640 UNKNOWN — Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user. Sep 16, 2026
CVE-2026-15639 UNKNOWN — An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the … Sep 16, 2026
CVE-2026-15638 UNKNOWN — An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. … Sep 16, 2026
CVE-2026-85893 HIGH 8.8 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. Sep 15, 2026
CVE-2026-69486 HIGH 8.8 Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Sep 15, 2026
CVE-2025-11395 MEDIUM 5.5 A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on … Sep 15, 2026
CVE-2026-83138 HIGH 8.0 Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability … Sep 15, 2026
CVE-2026-83137 HIGH 8.8 Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows … Sep 15, 2026
CVE-2026-83136 HIGH 8.8 Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows … Sep 15, 2026
CVE-2026-83135 HIGH 8.7 Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low … Sep 15, 2026
CVE-2026-83134 HIGH 7.7 Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low … Sep 15, 2026
CVE-2026-83133 HIGH 7.5 Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated … Sep 15, 2026
CVE-2026-83132 HIGH 8.1 Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low … Sep 15, 2026
CVE-2026-83131 HIGH 7.7 Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable … Sep 15, 2026
CVE-2026-83130 HIGH 7.1 Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows … Sep 15, 2026
CVE-2026-83129 HIGH 7.7 Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low … Sep 15, 2026