Fri, May 22 · 04:16 AM CDTCVE-2026-46595
10.0/10 · Must read/watchNVDvuln
Summary
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
CVECVE-2026-46595
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Aug 28 · 04:18 PM CDT
Tue, Nov 14 · 05:15 AM CSTCVE-2023-43902
9.8/10 · Must read/watchNVDvuln
Summary
Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.
CVECVE-2023-43902
SeverityCRITICAL
TypeUPDATED
PublishedTue, Nov 14 · 05:15 AM CST
ModifiedFri, Aug 28 · 04:16 PM CDT
Tue, Nov 21 · 10:15 PM CSTCVE-2023-49105
9.8/10 · Must read/watchNVDvuln
Summary
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for t
CVECVE-2023-49105
SeverityCRITICAL
TypeUPDATED
PublishedTue, Nov 21 · 10:15 PM CST
ModifiedFri, Aug 28 · 12:21 PM CDT
Fri, Apr 03 · 06:16 PM CDTCVE-2026-0545
9.8/10 · Must read/watchNVDvuln
Summary
In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job execution is enabled (`MLFLOW_SERVER_ENABLE_JOB_EXECUTION=true`) and any job functio
CVECVE-2026-0545
SeverityCRITICAL
TypeUPDATED
PublishedFri, Apr 03 · 06:16 PM CDT
ModifiedFri, Aug 28 · 04:17 PM CDT
Wed, Mar 11 · 05:16 PM CDTCVE-2026-1524
9.8/10 · Must read/watchNVDvuln
Summary
An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following conditions: If a neo4j admin configures two or more OIDC providers AND configures one or more of them to be an authorization provider AND configures one or more of them to
CVECVE-2026-1524
SeverityCRITICAL
TypeUPDATED
PublishedWed, Mar 11 · 05:16 PM CDT
ModifiedFri, Aug 28 · 04:08 PM CDT
Wed, Jun 17 · 03:16 PM CDTCVE-2026-47103
9.8/10 · Must read/watchNVDvuln
Summary
Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted ` ` attributes evaluated unsafely. The SCXMLProcessor passes attacker-controlled expression strings through a call chai
CVECVE-2026-47103
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jun 17 · 03:16 PM CDT
ModifiedFri, Aug 28 · 08:17 PM CDT
Tue, Jun 02 · 04:16 PM CDTCVE-2026-47117
9.8/10 · Must read/watchNVDvuln
Summary
OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used broad substring matching on the user-supplied model_name parameter, allowing a value such as attacker/foo-privacy-filter-bar to route through a path that loads Hugging Fac
CVECVE-2026-47117
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jun 02 · 04:16 PM CDT
ModifiedFri, Aug 28 · 08:17 PM CDT
Wed, Jun 24 · 04:16 PM CDTCVE-2026-56121
9.8/10 · Must read/watchNVDvuln
Summary
Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the registry server. The user_defined_function.body field of an OnDemandFeatureView spec is decoded from base64 and passed to d
CVECVE-2026-56121
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jun 24 · 04:16 PM CDT
ModifiedFri, Aug 28 · 04:18 PM CDT
Fri, May 22 · 04:16 PM CDTCVE-2026-39821
9.6/10 · Must read/watchNVDvuln
Summary
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a
CVECVE-2026-39821
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 PM CDT
ModifiedFri, Aug 28 · 04:17 PM CDT
Wed, May 13 · 04:16 PM CDTCVE-2026-42557
9.6/10 · Must read/watchNVDvuln
Summary
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on document.b
CVECVE-2026-42557
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 13 · 04:16 PM CDT
ModifiedFri, Aug 28 · 04:18 PM CDT
Wed, Jun 03 · 02:16 PM CDTCVE-2026-5241
9.6/10 · Must read/watchNVDvuln
Summary
A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, is overridden by untr
CVECVE-2026-5241
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jun 03 · 02:16 PM CDT
ModifiedFri, Aug 28 · 04:18 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedFri, Aug 28 · 04:17 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39830
9.1/10 · Must read/watchNVDvuln
Summary
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
CVECVE-2026-39830
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Aug 28 · 04:17 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-42508
9.1/10 · Must read/watchNVDvuln
Summary
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVECVE-2026-42508
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedFri, Aug 28 · 04:18 PM CDT
Wed, Apr 01 · 05:28 PM CDTCVE-2026-20094
8.8/10 · Worth your timeNVDvuln
Summary
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulnerability is due to improper validation of user-supplied input.
CVECVE-2026-20094
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 01 · 05:28 PM CDT
ModifiedFri, Aug 28 · 06:41 PM CDT
Tue, May 05 · 08:16 PM CDTCVE-2026-35397
8.8/10 · Worth your timeNVDvuln
Summary
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whose names begin with the same prefix as the root_dir. For example, with a root_dir na
CVECVE-2026-35397
SeverityHIGH
TypeUPDATED
PublishedTue, May 05 · 08:16 PM CDT
ModifiedFri, Aug 28 · 04:17 PM CDT
Wed, May 13 · 04:16 PM CDTCVE-2026-42266
8.8/10 · Worth your timeNVDvuln
Summary
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manage
CVECVE-2026-42266
SeverityHIGH
TypeUPDATED
PublishedWed, May 13 · 04:16 PM CDT
ModifiedFri, Aug 28 · 04:17 PM CDT
Wed, May 13 · 04:16 PM CDTCVE-2026-44293
8.8/10 · Worth your timeNVDvuln
Summary
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a non-string default value for a bytes field
CVECVE-2026-44293
SeverityHIGH
TypeUPDATED
PublishedWed, May 13 · 04:16 PM CDT
ModifiedFri, Aug 28 · 04:18 PM CDT
Thu, May 14 · 05:16 PM CDTCVE-2026-44513
8.8/10 · Worth your timeNVDvuln
Summary
Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omitting it, which is the default). The vulnerability has three variants, all sharing t
CVECVE-2026-44513
SeverityHIGH
TypeUPDATED
PublishedThu, May 14 · 05:16 PM CDT
ModifiedFri, Aug 28 · 04:18 PM CDT
Thu, Jul 23 · 12:18 PM CDTCVE-2026-65897
8.8/10 · Worth your timeNVDvuln
Summary
Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accounts to groups that grant api.super permissions. Attackers can create invitation records with elevated group membership, and when accepted, th
CVECVE-2026-65897
SeverityHIGH
TypeUPDATED
PublishedThu, Jul 23 · 12:18 PM CDT
ModifiedFri, Aug 28 · 04:18 PM CDT
Thu, Jun 11 · 05:16 PM CDTCVE-2026-44494
8.7/10 · Worth your timeNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack — intercepti
CVECVE-2026-44494
SeverityHIGH
TypeUPDATED
PublishedThu, Jun 11 · 05:16 PM CDT
ModifiedFri, Aug 28 · 04:18 PM CDT
Mon, Aug 03 · 01:16 AM CDTCVE-2026-12185
8.6/10 · Worth your timeNVDvuln
Summary
In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Castle for Java LTS before 2.73.12.
CVECVE-2026-12185
SeverityHIGH
TypeUPDATED
PublishedMon, Aug 03 · 01:16 AM CDT
ModifiedFri, Aug 28 · 02:42 PM CDT
Thu, Jun 11 · 05:16 PM CDTCVE-2026-44492
8.6/10 · Worth your timeNVDvuln
Summary
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:1, ::ffff:a9fe:a9fe) still routes throug
CVECVE-2026-44492
SeverityHIGH
TypeUPDATED
PublishedThu, Jun 11 · 05:16 PM CDT
ModifiedFri, Aug 28 · 04:18 PM CDT
Sun, Jun 28 · 02:16 AM CDTCVE-2026-58049
8.6/10 · Worth your timeNVDvuln
Summary
FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so a DLTA run on a PAL8 frame can access several bytes past the row allocation. A crafted media stream
CVECVE-2026-58049
SeverityHIGH
TypeUPDATED
PublishedSun, Jun 28 · 02:16 AM CDT
ModifiedFri, Aug 28 · 04:18 PM CDT
Thu, Jul 23 · 12:18 PM CDTCVE-2026-65895
8.5/10 · Worth your timeNVDvuln
Summary
Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and reco
CVECVE-2026-65895
SeverityHIGH
TypeUPDATED
PublishedThu, Jul 23 · 12:18 PM CDT
ModifiedFri, Aug 28 · 04:18 PM CDT