Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54227
Total
4299
Critical
16114
High
15798
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-102795 | CRITICAL | 9.3 | Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended … | Oct 02, 2026 |
| CVE-2026-102626 | UNKNOWN | — | An authenticated LimeSurvey Community Edition 7.4.0 user with the global Surveys: create permission can store a JavaScript-breaking value in the date_min attribute of a Date/Time … | Oct 02, 2026 |
| CVE-2026-104854 | UNKNOWN | — | Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0 until 22.7.9 and 23.1.2, Nx creates Unix domain sockets for its daemon and … | Oct 02, 2026 |
| CVE-2026-104853 | UNKNOWN | — | Nx is a monorepo solution for TypeScript and polyglot codebases. From 13.10.0 until 22.7.10 and 23.2.1, Nx migration planning reads the nx-migrations.migrations value from a … | Oct 02, 2026 |
| CVE-2026-104851 | HIGH | 8.8 | fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026.6.0, fsspec.implementations.reference.ReferenceFileSystem evaluates fields from Kerchunk reference JSON documents through unrestricted … | Oct 02, 2026 |
| CVE-2026-104849 | UNKNOWN | — | Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring … | Oct 02, 2026 |
| CVE-2026-104848 | UNKNOWN | — | Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.1, Tinypool constructs ThreadPool.options from a normal options object and reads the execArgv and … | Oct 02, 2026 |
| CVE-2026-96613 | MEDIUM | 6.5 | The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any … | Oct 02, 2026 |
| CVE-2026-94544 | UNKNOWN | — | Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without … | Oct 02, 2026 |
| CVE-2026-94543 | UNKNOWN | — | Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated … | Oct 02, 2026 |
| CVE-2026-94486 | UNKNOWN | — | Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the next dev development server exposes a Model Context Protocol endpoint … | Oct 02, 2026 |
| CVE-2026-94485 | UNKNOWN | — | Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the `next dev` development server exposes a Model Context Protocol endpoint … | Oct 02, 2026 |
| CVE-2026-94484 | UNKNOWN | — | Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, applications with a root-level catch-all page and statically generated … | Oct 02, 2026 |
| CVE-2026-94483 | UNKNOWN | — | Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resolution for a remote URL … | Oct 02, 2026 |
| CVE-2026-67989 | HIGH | 7.5 | crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x | Oct 02, 2026 |
| CVE-2026-51922 | UNKNOWN | — | agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution. | Oct 02, 2026 |
| CVE-2026-51918 | UNKNOWN | — | FinRobot 1.0.0 contains code injection in CodingUtils.create_file_with_code (). | Oct 02, 2026 |
| CVE-2026-51917 | UNKNOWN | — | FinRobot v1.0.0 is vulnerable to Code Injection in CodingUtils.modify_code. | Oct 02, 2026 |
| CVE-2026-51916 | HIGH | 7.5 | TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge_id} deletes the selected knowledge object without … | Oct 02, 2026 |
| CVE-2026-51915 | UNKNOWN | — | TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the tool controller. In affected source snapshots, get_tool and update_tool in superagi/controllers/tool.py accept a caller-supplied … | Oct 02, 2026 |
| CVE-2026-51914 | UNKNOWN | — | TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the agent template controller. In affected source snapshots, save_agent_as_template and publish_template in superagi/controllers/agent_template.py accept caller-supplied … | Oct 02, 2026 |
| CVE-2026-51911 | UNKNOWN | — | vanna v2.0.2 contains a code injection vulnerability in VannaBase.get_plotly_figure (src/vanna/legacy/base/base.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution. | Oct 02, 2026 |
| CVE-2026-51907 | HIGH | 8.1 | In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on … | Oct 02, 2026 |
| CVE-2026-51906 | UNKNOWN | — | In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image function, a path traversal vulnerability allows attackers to write downloaded images to arbitrary locations … | Oct 02, 2026 |
| CVE-2026-51904 | UNKNOWN | — | SuperAGI up to v0.0.14 contains an improper access control vulnerability in the agent execution controller. In affected source snapshots, create_agent_execution and create_agent_run in superagi/controllers/agent_execution.py accept … | Oct 02, 2026 |