Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54227
Total
4299
Critical
16114
High
15798
Medium
CVE ID Severity Score Description Published
CVE-2026-51901 UNKNOWN — SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allows authenticated users from one organization to schedule existing … Oct 02, 2026
CVE-2026-51899 MEDIUM 4.3 In SuperAGI v0.0.14 and prior, controller endpoints (/api/agents/create, /api/agents/schedule, /api/agents/delete, /api/agents/edit_schedule, /api/agents/stop_schedule) allow authenticated users from one organization to create, schedule, edit, stop, and delete … Oct 02, 2026
CVE-2026-51898 UNKNOWN — sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.execute. Oct 02, 2026
CVE-2026-104914 UNKNOWN — MISP contains an improper access control vulnerability in its attribute search and paginated attribute view endpoints. When a user queries for soft-deleted attributes (e.g., via … Oct 02, 2026
CVE-2026-104912 UNKNOWN — MISP contains an authorization flaw in its correlation handling during attribute searches. When a user performs an attribute search that triggers correlation lookups, the system … Oct 02, 2026
CVE-2026-104910 UNKNOWN — MISP contains an authorization bypass in the related events listing functionality. When a user requests the list of events correlated to a given event, the … Oct 02, 2026
CVE-2026-104908 UNKNOWN — MISP contains an improper input validation vulnerability in the decaying model import functionality. The import endpoint was intended to create a new decaying model belonging … Oct 02, 2026
CVE-2026-104907 UNKNOWN — MISP contains a cross-site scripting (XSS) vulnerability in the remote event preview page. When a linked (remote) MISP server is configured, the event preview renders … Oct 02, 2026
CVE-2026-104906 UNKNOWN — MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string properties was … Oct 02, 2026
CVE-2026-104901 UNKNOWN — MISP contains a cross-site scripting (XSS) vulnerability in the ID Translator feature. When a user views the ID Translator page, the application queries linked (remote) … Oct 02, 2026
CVE-2026-104900 UNKNOWN — MISP contains a stored cross-site scripting (XSS) vulnerability in the index table rendering of the remote event preview. The count field template escaped the associated … Oct 02, 2026
CVE-2026-104847 UNKNOWN — ProseMirror's view component renders and manages the editable browser interface for ProseMirror documents. Prior to 1.42.3, prosemirror-view paste handling accepts attacker-provided HTML whose clipboard slice … Oct 02, 2026
CVE-2026-104846 CRITICAL 9.8 Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node can pass … Oct 02, 2026
CVE-2026-104845 HIGH 7.5 Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.6.3, deserializeTypedArray in fromJSON and fromCrossJSON trusts a deserialized source value as … Oct 02, 2026
CVE-2026-104844 MEDIUM 5.9 PostCSS Selector Parser is a CSS selector parser that integrates with PostCSS but does not require it. Prior to 7.1.6, src/parser.js splitWord() can receive a … Oct 02, 2026
CVE-2026-104843 UNKNOWN — uv is a Python package and project manager written in Rust. From 0.12.7 until 0.12.18, uv wheel extraction on Windows can process a malicious wheel … Oct 02, 2026
CVE-2026-103648 CRITICAL 9.1 Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured … Oct 02, 2026
CVE-2026-103631 UNKNOWN — Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … Oct 02, 2026
CVE-2026-103630 UNKNOWN — Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted … Oct 02, 2026
CVE-2026-103629 UNKNOWN — Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security … Oct 02, 2026
CVE-2026-103628 CRITICAL 9.6 Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a … Oct 02, 2026
CVE-2026-103627 UNKNOWN — Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security … Oct 02, 2026
CVE-2026-103626 UNKNOWN — Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code … Oct 02, 2026
CVE-2026-103625 HIGH 8.8 Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML … Oct 02, 2026
CVE-2026-103624 UNKNOWN — Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process … Oct 02, 2026