Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26391
Total
1955
Critical
7971
High
8223
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-44837 | MEDIUM | 5.9 | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes … | May 26, 2026 |
| CVE-2026-44836 | MEDIUM | 6.5 | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the preview route derives an … | May 26, 2026 |
| CVE-2026-44708 | MEDIUM | 6.1 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the mistune math plugin renders inline math ($...$) and block math ($$...$$) … | May 26, 2026 |
| CVE-2026-44451 | CRITICAL | 9.3 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied TSX via Sucrase and evaluates it with new Function, … | May 26, 2026 |
| CVE-2026-44450 | CRITICAL | 9.9 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command field against an allowlist of binary names … | May 26, 2026 |
| CVE-2026-44449 | CRITICAL | 9.1 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, when the primary toSmbPath(fullPath) call throws, the method falls back to a dirname/basename split and … | May 26, 2026 |
| CVE-2026-44444 | CRITICAL | 9.1 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install without the --ignore-scripts flag before running the … | May 26, 2026 |
| CVE-2026-44443 | MEDIUM | 4.8 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, consumeNonce() only checks that the module-level variable is set and unexpired. It does not validate … | May 26, 2026 |
| CVE-2026-44209 | HIGH | 7.5 | Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Environment() (unsandboxed) to render prompt templates. Applications that … | May 26, 2026 |
| CVE-2026-42337 | UNKNOWN | — | MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a broken access control vulnerability in the OSS file service … | May 26, 2026 |
| CVE-2026-42336 | UNKNOWN | — | MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in the OSS file … | May 26, 2026 |
| CVE-2026-42335 | UNKNOWN | — | MaxKB is an open-source AI assistant for enterprise. Prior to 2.8.1, MaxKB v2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in … | May 26, 2026 |
| CVE-2026-36239 | UNKNOWN | — | PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality | May 26, 2026 |
| CVE-2025-68711 | UNKNOWN | — | AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is … | May 26, 2026 |
| CVE-2025-68708 | UNKNOWN | — | SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an … | May 26, 2026 |
| CVE-2025-14361 | HIGH | 7.1 | Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Woocommerce Envato Affiliates: from n/a through … | May 26, 2026 |
| CVE-2026-9575 | HIGH | 7.3 | A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown processing of the file /admin/modules/class/index.php?view=view. The manipulation of … | May 26, 2026 |
| CVE-2026-9574 | HIGH | 7.3 | A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code of the file /admin/modules/student/trans.php. Executing a manipulation of … | May 26, 2026 |
| CVE-2026-9573 | HIGH | 7.3 | A vulnerability was detected in itsourcecode Student Transcript Processing System 1.0. This affects an unknown part of the file /admin/modules/student/index.php?view=view. Performing a manipulation of the … | May 26, 2026 |
| CVE-2026-8453 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this … | May 26, 2026 |
| CVE-2026-44833 | MEDIUM | 5.9 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via … | May 26, 2026 |
| CVE-2026-44832 | HIGH | 8.8 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by … | May 26, 2026 |
| CVE-2026-44831 | MEDIUM | 4.8 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, resulting in … | May 26, 2026 |
| CVE-2026-44214 | MEDIUM | 5.8 | eventsource-encoder encodes events as well-formed EventSource/Server Sent Event (SSE) messages. Prior to 1.0.2, eventsource-encoder does not sanitize the event or id fields of an EventSourceMessage … | May 26, 2026 |
| CVE-2026-27331 | MEDIUM | 6.3 | Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpTravelly: from n/a through 2.1.5. | May 26, 2026 |