Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26391
Total
1955
Critical
7971
High
8223
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-46280 | MEDIUM | 5.5 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be able to cause unexpected … | May 26, 2026 |
| CVE-2025-43451 | MEDIUM | 5.5 | A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to access … | May 26, 2026 |
| CVE-2025-43306 | HIGH | 7.8 | A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app … | May 26, 2026 |
| CVE-2025-43290 | MEDIUM | 5.5 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. An app may … | May 26, 2026 |
| CVE-2025-43289 | MEDIUM | 5.5 | A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26. A malicious app … | May 26, 2026 |
| CVE-2026-9642 | CRITICAL | 9.8 | There is a mitigation bypass / (incomplete fix) for CVE-2025-62582 (Unauthenticated Remote Database Access) An unauthenticated remote attacker can access configured databases in a DIAView … | May 26, 2026 |
| CVE-2026-9583 | MEDIUM | 4.3 | A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php … | May 26, 2026 |
| CVE-2026-9582 | MEDIUM | 4.3 | A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects an unknown function. Performing a manipulation … | May 26, 2026 |
| CVE-2026-9581 | MEDIUM | 6.3 | A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to improper … | May 26, 2026 |
| CVE-2026-9580 | HIGH | 7.3 | A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation causes improper access … | May 26, 2026 |
| CVE-2026-9579 | MEDIUM | 6.3 | A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the component SysUser. The manipulation of … | May 26, 2026 |
| CVE-2026-8676 | HIGH | 8.8 | An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bonded device and creating a … | May 26, 2026 |
| CVE-2026-48593 | UNKNOWN | — | Uncontrolled Resource Consumption vulnerability in oban-bg oban_web ('Elixir.Oban.Web.CronExpr' modules) allows memory exhaustion via unbounded cron range expansion. An attacker with access to schedule cron jobs … | May 26, 2026 |
| CVE-2026-48592 | UNKNOWN | — | Missing Authorization vulnerability in oban-bg oban_web ('Elixir.Oban.Web.Jobs.DetailComponent' modules) allows unauthorized job worker substitution. The handle_event("save-job", ...) handler in 'Elixir.Oban.Web.Jobs.DetailComponent' does not perform an authorization check, … | May 26, 2026 |
| CVE-2026-47672 | MEDIUM | 6.5 | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. In 1.2.4 and earlier, any network-reachable caller can write arbitrary documents … | May 26, 2026 |
| CVE-2026-45575 | HIGH | 7.4 | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection … | May 26, 2026 |
| CVE-2026-45413 | UNKNOWN | — | MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, user passwords are stored using unsalted MD5 hashes, making them trivially crackable via rainbow … | May 26, 2026 |
| CVE-2026-45412 | UNKNOWN | — | MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via work_flow_template Import. Authenticated users can supply arbitrary URLs in work_flow_template.downloadUrl which are … | May 26, 2026 |
| CVE-2026-44899 | MEDIUM | 4.7 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the :width: and :height: options with a … | May 26, 2026 |
| CVE-2026-44898 | MEDIUM | 6.1 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_toc_ul() builds a <ul> table-of-contents tree from a list of (level, id, … | May 26, 2026 |
| CVE-2026-44897 | MEDIUM | 6.1 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, HTMLRenderer.heading() builds the opening <hN> tag by string-concatenating the id attribute value … | May 26, 2026 |
| CVE-2026-44896 | UNKNOWN | — | Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and realier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options directly … | May 26, 2026 |
| CVE-2026-44847 | HIGH | 7.5 | MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/webhook/{trigger_id}) is accessible without authentication. The WebhookAuth class unconditionally returns … | May 26, 2026 |
| CVE-2026-44844 | UNKNOWN | — | eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to … | May 26, 2026 |
| CVE-2026-44843 | HIGH | 8.2 | LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, … | May 26, 2026 |