Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26391
Total
1955
Critical
7971
High
8223
Medium
CVE ID Severity Score Description Published
CVE-2025-46280 MEDIUM 5.5 An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be able to cause unexpected … May 26, 2026
CVE-2025-43451 MEDIUM 5.5 A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to access … May 26, 2026
CVE-2025-43306 HIGH 7.8 A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app … May 26, 2026
CVE-2025-43290 MEDIUM 5.5 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may … May 26, 2026
CVE-2025-43289 MEDIUM 5.5 A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app … May 26, 2026
CVE-2026-9642 CRITICAL 9.8 There is a mitigation bypass / (incomplete fix) for CVE-2025-62582 (Unauthenticated Remote Database Access) An unauthenticated remote attacker can access configured databases in a DIAView … May 26, 2026
CVE-2026-9583 MEDIUM 4.3 A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php … May 26, 2026
CVE-2026-9582 MEDIUM 4.3 A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects an unknown function. Performing a manipulation … May 26, 2026
CVE-2026-9581 MEDIUM 6.3 A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to improper … May 26, 2026
CVE-2026-9580 HIGH 7.3 A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation causes improper access … May 26, 2026
CVE-2026-9579 MEDIUM 6.3 A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the component SysUser. The manipulation of … May 26, 2026
CVE-2026-8676 HIGH 8.8 An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a … May 26, 2026
CVE-2026-48593 UNKNOWN Uncontrolled Resource Consumption vulnerability in oban-bg oban_web ('Elixir.Oban.Web.CronExpr' modules) allows memory exhaustion via unbounded cron range expansion. An attacker with access to schedule cron jobs … May 26, 2026
CVE-2026-48592 UNKNOWN Missing Authorization vulnerability in oban-bg oban_web ('Elixir.Oban.Web.Jobs.DetailComponent' modules) allows unauthorized job worker substitution. The handle_event("save-job", ...) handler in 'Elixir.Oban.Web.Jobs.DetailComponent' does not perform an authorization check, … May 26, 2026
CVE-2026-47672 MEDIUM 6.5 epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. In 1.2.4 and earlier, any network-reachable caller can write arbitrary documents … May 26, 2026
CVE-2026-45575 HIGH 7.4 epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection … May 26, 2026
CVE-2026-45413 UNKNOWN MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, user passwords are stored using unsalted MD5 hashes, making them trivially crackable via rainbow … May 26, 2026
CVE-2026-45412 UNKNOWN MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via work_flow_template Import. Authenticated users can supply arbitrary URLs in work_flow_template.downloadUrl which are … May 26, 2026
CVE-2026-44899 MEDIUM 4.7 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the :width: and :height: options with a … May 26, 2026
CVE-2026-44898 MEDIUM 6.1 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_toc_ul() builds a <ul> table-of-contents tree from a list of (level, id, … May 26, 2026
CVE-2026-44897 MEDIUM 6.1 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, HTMLRenderer.heading() builds the opening <hN> tag by string-concatenating the id attribute value … May 26, 2026
CVE-2026-44896 UNKNOWN Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and realier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly … May 26, 2026
CVE-2026-44847 HIGH 7.5 MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/webhook/{trigger_id}) is accessible without authentication. The WebhookAuth class unconditionally returns … May 26, 2026
CVE-2026-44844 UNKNOWN eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to … May 26, 2026
CVE-2026-44843 HIGH 8.2 LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, … May 26, 2026