Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54227
Total
4299
Critical
16114
High
15798
Medium
CVE ID Severity Score Description Published
CVE-2026-82039 HIGH 8.8 UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values … Oct 02, 2026
CVE-2026-39718 HIGH 8.8 Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet allows Cross Site Request Forgery.This issue affects Wallstreet: from n/a through 2.8.6. Oct 02, 2026
CVE-2026-12392 MEDIUM 5.3 An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret … Oct 02, 2026
CVE-2026-104994 LOW 2.5 Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using … Oct 02, 2026
CVE-2026-104991 HIGH 7.1 Phproject before 1.8.7 contains a missing object-level authorization vulnerability in the REST API issue endpoints (single_get, single_comments, single_comments_post) that allows authenticated API key holders to … Oct 02, 2026
CVE-2026-104988 HIGH 8.1 A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without … Oct 02, 2026
CVE-2026-104873 UNKNOWN — LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. From 0.1.45 until 0.4.4, … Oct 02, 2026
CVE-2026-104872 MEDIUM 5.8 OpenTelemetry JavaScript Contrib provides instrumentation libraries for collecting telemetry from JavaScript applications. Prior to versions 0.66.0 of @opentelemetry/instrumentation-cassandra-driver, 0.65.0 of @opentelemetry/instrumentation-knex, 0.67.0 of @opentelemetry/instrumentation-mongoose, @opentelemetry/instrumentation-mysql, … Oct 02, 2026
CVE-2026-104871 UNKNOWN — The Angular SSR is a server-rise rendering tool for Angular applications. Prior to versions 20.3.36, 21.2.23, and 22.1.7, the CommonEngine retrieveSSGPage prerendered-page retrieval logic in … Oct 02, 2026
CVE-2026-104019 CRITICAL 9.0 OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before … Oct 02, 2026
CVE-2026-103918 MEDIUM 6.5 oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.10, the @orpc/zod ZodSmartCoercionPlugin and experimental_ZodSmartCoercionPlugin … Oct 02, 2026
CVE-2026-103036 MEDIUM 6.5 oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.9, the @orpc/json-schema SmartCoercionPlugin uses JsonSchemaCoercer … Oct 02, 2026
CVE-2026-96940 HIGH 8.8 Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. Oct 02, 2026
CVE-2026-19856 MEDIUM 6.5 The All in One SEO WordPress plugin before 5.0.2.1 does not correctly determine which shortcodes are present in content derived from user input before deciding … Oct 02, 2026
CVE-2026-103958 HIGH 7.6 Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to … Oct 02, 2026
CVE-2026-103957 MEDIUM 6.2 Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the access token … Oct 02, 2026
CVE-2026-103956 CRITICAL 10.0 Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent … Oct 02, 2026
CVE-2023-54405 CRITICAL 9.8 H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that … Oct 02, 2026
CVE-2020-37278 HIGH 7.5 Weaver e-Bridge contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to access arbitrary files on the host system by supplying a file: … Oct 02, 2026
CVE-2014-125130 HIGH 7.5 CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive … Oct 02, 2026
CVE-2026-64818 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Oct 02, 2026
CVE-2026-59265 UNKNOWN — A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) … Oct 02, 2026
CVE-2026-104861 HIGH 7.5 probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/parse_sync/svg.js and lib/parse_stream/svg.js use the searching regular expression /<[-_.:a-zA-Z0-9][^>]*>/, which repeatedly scans to … Oct 02, 2026
CVE-2026-104859 UNKNOWN — Nx is a monorepo solution for TypeScript and polyglot codebases. From 21.4.0 until 22.7.8 and from 23.0.0 until 23.1.1, the @nx/docker release pipeline builds docker … Oct 02, 2026
CVE-2026-104855 UNKNOWN — Wasmtime is a runtime for WebAssembly. From 46.0.0 until 46.0.2 and 47.0.3, fuel and epoch preemption checks inside bulk operations including memory.copy, table.grow, and array.copy … Oct 02, 2026