Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54227
Total
4299
Critical
16114
High
15798
Medium
CVE ID Severity Score Description Published
CVE-2026-102795 CRITICAL 9.3 Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended … Oct 02, 2026
CVE-2026-102626 UNKNOWN — An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time … Oct 02, 2026
CVE-2026-104854 UNKNOWN — Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0 until 22.7.9 and 23.1.2, Nx creates Unix domain sockets for its daemon and … Oct 02, 2026
CVE-2026-104853 UNKNOWN — Nx is a monorepo solution for TypeScript and polyglot codebases. From 13.10.0 until 22.7.10 and 23.2.1, Nx migration planning reads the nx-migrations.migrations value from a … Oct 02, 2026
CVE-2026-104851 HIGH 8.8 fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026.6.0, fsspec.implementations.reference.ReferenceFileSystem evaluates fields from Kerchunk reference JSON documents through unrestricted … Oct 02, 2026
CVE-2026-104849 UNKNOWN — Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring … Oct 02, 2026
CVE-2026-104848 UNKNOWN — Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.1, Tinypool constructs ThreadPool.options from a normal options object and reads the execArgv and … Oct 02, 2026
CVE-2026-96613 MEDIUM 6.5 The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any … Oct 02, 2026
CVE-2026-94544 UNKNOWN — Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without … Oct 02, 2026
CVE-2026-94543 UNKNOWN — Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated … Oct 02, 2026
CVE-2026-94486 UNKNOWN — Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the next dev development server exposes a Model Context Protocol endpoint … Oct 02, 2026
CVE-2026-94485 UNKNOWN — Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the `next dev` development server exposes a Model Context Protocol endpoint … Oct 02, 2026
CVE-2026-94484 UNKNOWN — Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, applications with a root-level catch-all page and statically generated … Oct 02, 2026
CVE-2026-94483 UNKNOWN — Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resolution for a remote URL … Oct 02, 2026
CVE-2026-67989 HIGH 7.5 crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x Oct 02, 2026
CVE-2026-51922 UNKNOWN — agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution. Oct 02, 2026
CVE-2026-51918 UNKNOWN — FinRobot 1.0.0 contains code injection in CodingUtils.create_file_with_code (). Oct 02, 2026
CVE-2026-51917 UNKNOWN — FinRobot v1.0.0 is vulnerable to Code Injection in CodingUtils.modify_code. Oct 02, 2026
CVE-2026-51916 HIGH 7.5 TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge_id} deletes the selected knowledge object without … Oct 02, 2026
CVE-2026-51915 UNKNOWN — TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the tool controller. In affected source snapshots, get_tool and update_tool in superagi/controllers/tool.py accept a caller-supplied … Oct 02, 2026
CVE-2026-51914 UNKNOWN — TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the agent template controller. In affected source snapshots, save_agent_as_template and publish_template in superagi/controllers/agent_template.py accept caller-supplied … Oct 02, 2026
CVE-2026-51911 UNKNOWN — vanna v2.0.2 contains a code injection vulnerability in VannaBase.get_plotly_figure (src/vanna/legacy/base/base.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution. Oct 02, 2026
CVE-2026-51907 HIGH 8.1 In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on … Oct 02, 2026
CVE-2026-51906 UNKNOWN — In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image function, a path traversal vulnerability allows attackers to write downloaded images to arbitrary locations … Oct 02, 2026
CVE-2026-51904 UNKNOWN — SuperAGI up to v0.0.14 contains an improper access control vulnerability in the agent execution controller. In affected source snapshots, create_agent_execution and create_agent_run in superagi/controllers/agent_execution.py accept … Oct 02, 2026