Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57401
Total
4583
Critical
17032
High
16919
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-90809 | HIGH | 7.3 | A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. … | Sep 14, 2026 |
| CVE-2026-90808 | MEDIUM | 6.3 | A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation … | Sep 14, 2026 |
| CVE-2026-89023 | HIGH | 8.6 | ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access … | Sep 14, 2026 |
| CVE-2026-89021 | MEDIUM | 6.9 | MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container … | Sep 14, 2026 |
| CVE-2026-89020 | MEDIUM | 4.3 | MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated … | Sep 14, 2026 |
| CVE-2026-86830 | HIGH | 7.2 | Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with … | Sep 14, 2026 |
| CVE-2026-82519 | MEDIUM | 4.3 | Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely … | Sep 14, 2026 |
| CVE-2026-82049 | UNKNOWN | — | In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic … | Sep 14, 2026 |
| CVE-2026-82035 | HIGH | 7.1 | PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is … | Sep 14, 2026 |
| CVE-2026-77884 | UNKNOWN | — | Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 … | Sep 14, 2026 |
| CVE-2026-59178 | CRITICAL | 9.8 | ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` … | Sep 14, 2026 |
| CVE-2026-19543 | MEDIUM | 6.2 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and … | Sep 14, 2026 |
| CVE-2026-18515 | MEDIUM | 4.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when … | Sep 14, 2026 |
| CVE-2026-18151 | MEDIUM | 4.2 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition during the WebSocket … | Sep 14, 2026 |
| CVE-2026-15893 | MEDIUM | 6.5 | net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachable_time as min_reachable + sys_rand32_get() % (max_reachable - min_reachable), where min_reachable = base/2 and max_reachable … | Sep 14, 2026 |
| CVE-2013-1446 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Was assigned for an old issue in the brltty daemon … | Sep 14, 2026 |
| CVE-2026-91081 | MEDIUM | 5.8 | Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public … | Sep 14, 2026 |
| CVE-2026-91080 | HIGH | 7.5 | webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers … | Sep 14, 2026 |
| CVE-2026-91079 | HIGH | 8.5 | Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply … | Sep 14, 2026 |
| CVE-2026-91021 | MEDIUM | 5.4 | Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping … | Sep 14, 2026 |
| CVE-2026-90946 | HIGH | 7.5 | DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no … | Sep 14, 2026 |
| CVE-2026-90945 | CRITICAL | 9.8 | Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge … | Sep 14, 2026 |
| CVE-2026-90944 | HIGH | 8.2 | Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply … | Sep 14, 2026 |
| CVE-2026-90942 | CRITICAL | 9.6 | Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers … | Sep 14, 2026 |
| CVE-2026-90807 | MEDIUM | 6.3 | A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the file src/modules/agent-to-agent/agent-route.ts of the component Attachment Handler. … | Sep 14, 2026 |