Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54227
Total
4299
Critical
16114
High
15798
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-51901 | UNKNOWN | — | SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allows authenticated users from one organization to schedule existing … | Oct 02, 2026 |
| CVE-2026-51899 | MEDIUM | 4.3 | In SuperAGI v0.0.14 and prior, controller endpoints (/api/agents/create, /api/agents/schedule, /api/agents/delete, /api/agents/edit_schedule, /api/agents/stop_schedule) allow authenticated users from one organization to create, schedule, edit, stop, and delete … | Oct 02, 2026 |
| CVE-2026-51898 | UNKNOWN | — | sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.execute. | Oct 02, 2026 |
| CVE-2026-104914 | UNKNOWN | — | MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints. When a user queries for soft-deleted attributes (e.g., via … | Oct 02, 2026 |
| CVE-2026-104912 | UNKNOWN | — | MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system … | Oct 02, 2026 |
| CVE-2026-104910 | UNKNOWN | — | MISP contains an authorization bypass in the related events listing functionality. When a user requests the list of events correlated to a given event, the … | Oct 02, 2026 |
| CVE-2026-104908 | UNKNOWN | — | MISP contains an improper input validation vulnerability in the decaying model import functionality. The import endpoint was intended to create a new decaying model belonging … | Oct 02, 2026 |
| CVE-2026-104907 | UNKNOWN | — | MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders … | Oct 02, 2026 |
| CVE-2026-104906 | UNKNOWN | — | MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string properties was … | Oct 02, 2026 |
| CVE-2026-104901 | UNKNOWN | — | MISP contains a cross-site scripting (XSS) vulnerability in the ID Translator feature. When a user views the ID Translator page, the application queries linked (remote) … | Oct 02, 2026 |
| CVE-2026-104900 | UNKNOWN | — | MISP contains a stored cross-site scripting (XSS) vulnerability in the index table rendering of the remote event preview. The count field template escaped the associated … | Oct 02, 2026 |
| CVE-2026-104847 | UNKNOWN | — | ProseMirror's view component renders and manages the editable browser interface for ProseMirror documents. Prior to 1.42.3, prosemirror-view paste handling accepts attacker-provided HTML whose clipboard slice … | Oct 02, 2026 |
| CVE-2026-104846 | CRITICAL | 9.8 | Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node can pass … | Oct 02, 2026 |
| CVE-2026-104845 | HIGH | 7.5 | Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.6.3, deserializeTypedArray in fromJSON and fromCrossJSON trusts a deserialized source value as … | Oct 02, 2026 |
| CVE-2026-104844 | MEDIUM | 5.9 | PostCSS Selector Parser is a CSS selector parser that integrates with PostCSS but does not require it. Prior to 7.1.6, src/parser.js splitWord() can receive a … | Oct 02, 2026 |
| CVE-2026-104843 | UNKNOWN | — | uv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel … | Oct 02, 2026 |
| CVE-2026-103648 | CRITICAL | 9.1 | Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured … | Oct 02, 2026 |
| CVE-2026-103631 | UNKNOWN | — | Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … | Oct 02, 2026 |
| CVE-2026-103630 | UNKNOWN | — | Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted … | Oct 02, 2026 |
| CVE-2026-103629 | UNKNOWN | — | Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security … | Oct 02, 2026 |
| CVE-2026-103628 | CRITICAL | 9.6 | Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a … | Oct 02, 2026 |
| CVE-2026-103627 | UNKNOWN | — | Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security … | Oct 02, 2026 |
| CVE-2026-103626 | UNKNOWN | — | Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code … | Oct 02, 2026 |
| CVE-2026-103625 | HIGH | 8.8 | Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … | Oct 02, 2026 |
| CVE-2026-103624 | UNKNOWN | — | Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process … | Oct 02, 2026 |