Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

57401
Total
4583
Critical
17032
High
16919
Medium
CVE ID Severity Score Description Published
CVE-2026-90806 MEDIUM 6.3 A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk … Sep 14, 2026
CVE-2026-90805 HIGH 7.3 A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. This affects an unknown part of the file doctorlogin.php. Executing a manipulation of the … Sep 14, 2026
CVE-2026-86836 UNKNOWN — In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the … Sep 14, 2026
CVE-2026-85921 HIGH 8.2 Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. Sep 14, 2026
CVE-2026-85892 HIGH 7.8 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally. Sep 14, 2026
CVE-2026-73494 HIGH 7.4 blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.0-M1 until 1.0.0-M42, five HTTP/1.1 … Sep 14, 2026
CVE-2026-70658 HIGH 7.4 Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11.6.2, Pay::Webhooks::PaddleBillingController#valid_signature? in app/controllers/pay/webhooks/paddle_billing_controller.rb compares the computed 64-character SHA-256 HMAC with … Sep 14, 2026
CVE-2026-57583 LOW 3.3 OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Prior to @openzeppelin/wizard 0.10.11, @openzeppelin/wizard-cairo 3.0.1, @openzeppelin/wizard-stellar … Sep 14, 2026
CVE-2026-57581 MEDIUM 5.3 DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applications with configured file upload storage allow unauthenticated users … Sep 14, 2026
CVE-2026-57578 UNKNOWN — DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, AuthorizeActionFilter performs no authorization because its explicit ICommandActionFilter.OnCommandExecutingAsync, IViewModelActionFilter.OnViewModelCreatedAsync, … Sep 14, 2026
CVE-2026-57577 UNKNOWN — DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, a route containing multiple unconstrained parameters in one path … Sep 14, 2026
CVE-2026-57570 MEDIUM 6.5 backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 … Sep 14, 2026
CVE-2026-55866 LOW 3.7 SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34.0 until 1.54.0, SpiceDB can return PERMISSIONSHIP_HAS_PERMISSION instead of PERMISSIONSHIP_CONDITIONAL_PERMISSION … Sep 14, 2026
CVE-2026-55847 MEDIUM 6.1 Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js helper at allure-generator/src/main/javascript/helpers/ansi.js passes attacker-influenced … Sep 14, 2026
CVE-2026-55846 MEDIUM 6.2 Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP server started by allure serve … Sep 14, 2026
CVE-2026-55832 MEDIUM 6.1 Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2, the tract-onnx crate passes the attacker-controlled external_data location … Sep 14, 2026
CVE-2026-55253 HIGH 7.7 LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0, MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search() incorporate filter dictionaries into … Sep 14, 2026
CVE-2026-55091 HIGH 7.5 flat-to-nested converts a hierarchy from a flat representation to a nested representation. Prior to 1.1.2, FlatToNested.prototype.convert in index.js uses attacker-influenced id and parent record fields … Sep 14, 2026
CVE-2026-54723 MEDIUM 6.5 devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a server configured with the primary … Sep 14, 2026
CVE-2026-54567 HIGH 7.5 Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the case-preserving … Sep 14, 2026
CVE-2026-54182 HIGH 8.1 backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to … Sep 14, 2026
CVE-2026-54181 MEDIUM 5.4 backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 … Sep 14, 2026
CVE-2026-54180 HIGH 7.6 backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 … Sep 14, 2026
CVE-2026-54178 HIGH 8.1 backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to … Sep 14, 2026
CVE-2026-54177 MEDIUM 6.6 backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 … Sep 14, 2026