Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54298
Total
4306
Critical
16144
High
15836
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-101907 | UNKNOWN | — | Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the maxRedirects: 0 redirect policy. An … | Sep 28, 2026 |
| CVE-2026-101906 | UNKNOWN | — | Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.0 until 1.20.0, Axios shouldBypassProxy applies a quadratic trailing-dot regular expression to redirect … | Sep 28, 2026 |
| CVE-2026-101905 | UNKNOWN | — | Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without … | Sep 28, 2026 |
| CVE-2026-101904 | UNKNOWN | — | Axios is a promise-based HTTP client for the browser and Node.js. From 1.0.0 until 1.20.0, the dispatchRequest function normalizes inherited Object.prototype.headers from a replacement request … | Sep 28, 2026 |
| CVE-2026-101903 | UNKNOWN | — | Axios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regular expression allows slash characters on both … | Sep 28, 2026 |
| CVE-2026-101902 | UNKNOWN | — | Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method … | Sep 28, 2026 |
| CVE-2026-101901 | UNKNOWN | — | Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error handling for a ClientHttp2Session … | Sep 28, 2026 |
| CVE-2026-101900 | UNKNOWN | — | Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited Symbol.toStringTag, append, and getHeaders properties while resolving … | Sep 28, 2026 |
| CVE-2026-101898 | UNKNOWN | — | Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Axios HTTP/2 request setup does not consistently apply proxy settings … | Sep 28, 2026 |
| CVE-2026-101102 | MEDIUM | 6.3 | A vulnerability was found in deepseek-ai deepseek-harness up to 0.1.0-rc.7. Impacted is the function run_code of the component Code Mode Sandbox. The manipulation results in … | Sep 28, 2026 |
| CVE-2026-101101 | MEDIUM | 4.3 | A vulnerability has been found in ag-ui-protocol ag-ui up to 2026-09-07. This issue affects the function JSON.parse of the file legacy/convert.ts of the component Middleware. … | Sep 28, 2026 |
| CVE-2026-101100 | MEDIUM | 5.4 | A flaw has been found in ag-ui-protocol ag-ui up to 2026-09-07. This vulnerability affects the function FilterToolCallsMiddleware of the file sdks/typescript/packages/client/src/middleware/filter-tool-calls.ts of the component Middleware. … | Sep 28, 2026 |
| CVE-2026-101099 | MEDIUM | 4.3 | A vulnerability was detected in ag-ui-protocol ag-ui up to 2026-09-23. This affects an unknown part of the file SseParser.kt of the component Kotlin Community SDK. … | Sep 28, 2026 |
| CVE-2026-88816 | UNKNOWN | — | DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName. fetchrow_hashref uses the string pointer of the FetchHashKeyName attribute as the … | Sep 28, 2026 |
| CVE-2026-88815 | UNKNOWN | — | DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv. When casting to SQL_NUMERIC, sql_type_cast_svpv passes the string pointer and length … | Sep 28, 2026 |
| CVE-2026-87969 | UNKNOWN | — | An OS command injection vulnerability in the WatchGuard AP diagnostic CLI allows an authenticated administrator to execute arbitrary operating system commands by supplying crafted input. | Sep 28, 2026 |
| CVE-2026-87114 | HIGH | 7.1 | A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting … | Sep 28, 2026 |
| CVE-2026-86102 | UNKNOWN | — | An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell … | Sep 28, 2026 |
| CVE-2026-85644 | UNKNOWN | — | XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference. The wrapper function XS::Parse::Infix generates for a list-associative infix operator … | Sep 28, 2026 |
| CVE-2026-58464 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 28, 2026 |
| CVE-2026-58463 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 28, 2026 |
| CVE-2026-55096 | HIGH | 7.1 | fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP tools accept files as a list of http(s) URLs, which the server … | Sep 28, 2026 |
| CVE-2026-54160 | HIGH | 8.2 | Network UPS Tools is a collection of programs which provide a common interface for monitoring and administering UPS, PDU and SCD hardware. Prior to commits … | Sep 28, 2026 |
| CVE-2026-48100 | UNKNOWN | — | Payy is an Ethereum L2 zk-rollup for privacy preserving and regulatory compliant transactions. Prior to version 1.3.0, agg_agg forwards the compacted message stream from its … | Sep 28, 2026 |
| CVE-2026-101894 | CRITICAL | 9.1 | The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not … | Sep 28, 2026 |