Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56907
Total
4512
Critical
16897
High
16715
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-92217 | MEDIUM | 6.3 | A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/message-processor.ts of the component Message Parsing. This … | Sep 16, 2026 |
| CVE-2026-92216 | MEDIUM | 4.3 | A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component … | Sep 16, 2026 |
| CVE-2026-92215 | HIGH | 7.3 | A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the function httpx.get of the file agent_sdks/python/a2ui_agent/src/a2ui/extensions/file_resolve/file_resolver.py of the … | Sep 16, 2026 |
| CVE-2026-92214 | LOW | 3.5 | A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/client/angular/projects/a2a-chat-canvas/src/lib/services/sanitizer-markdown-renderer-service.ts of the component a2a-chat-canvas. Executing … | Sep 16, 2026 |
| CVE-2026-92213 | MEDIUM | 5.5 | A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This impacts the function z.any of the file renderers/web_core/src/v0_9/schema/server-to-client.ts of the component Angular Renderer. Performing … | Sep 16, 2026 |
| CVE-2026-92184 | MEDIUM | 6.3 | A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component Multimodal Content. The … | Sep 16, 2026 |
| CVE-2026-73460 | MEDIUM | 6.1 | On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause … | Sep 16, 2026 |
| CVE-2026-73459 | HIGH | 7.4 | On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate … | Sep 16, 2026 |
| CVE-2026-73446 | HIGH | 7.4 | On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit … | Sep 16, 2026 |
| CVE-2026-15640 | UNKNOWN | — | Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user. | Sep 16, 2026 |
| CVE-2026-15639 | UNKNOWN | — | An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the … | Sep 16, 2026 |
| CVE-2026-15638 | UNKNOWN | — | An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. … | Sep 16, 2026 |
| CVE-2026-85893 | HIGH | 8.8 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. | Sep 15, 2026 |
| CVE-2026-69486 | HIGH | 8.8 | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | Sep 15, 2026 |
| CVE-2025-11395 | MEDIUM | 5.5 | A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on … | Sep 15, 2026 |
| CVE-2026-83138 | HIGH | 8.0 | Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability … | Sep 15, 2026 |
| CVE-2026-83137 | HIGH | 8.8 | Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows … | Sep 15, 2026 |
| CVE-2026-83136 | HIGH | 8.8 | Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows … | Sep 15, 2026 |
| CVE-2026-83135 | HIGH | 8.7 | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low … | Sep 15, 2026 |
| CVE-2026-83134 | HIGH | 7.7 | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low … | Sep 15, 2026 |
| CVE-2026-83133 | HIGH | 7.5 | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated … | Sep 15, 2026 |
| CVE-2026-83132 | HIGH | 8.1 | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low … | Sep 15, 2026 |
| CVE-2026-83131 | HIGH | 7.7 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable … | Sep 15, 2026 |
| CVE-2026-83130 | HIGH | 7.1 | Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows … | Sep 15, 2026 |
| CVE-2026-83129 | HIGH | 7.7 | Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low … | Sep 15, 2026 |