Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 301–325 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-85769 MEDIUM 6.5 2026-09-04 A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migr…
CVE-2026-85730 NONE Patched — 2026-09-04 smol-toml is a small, fast, and correct TOML parser and serializer. Prior to 1.7.1, parse() can enter an infinite loop when a value inside an array or inline table is follo…
CVE-2026-85704 LOW 3.7 2026-09-04 A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file s…
CVE-2026-85703 MEDIUM 6.5 2026-09-04 A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/b…
CVE-2026-85702 HIGH 7.3 2026-09-04 A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file …
CVE-2026-85701 MEDIUM 5.3 2026-09-04 A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the fi…
CVE-2026-85700 MEDIUM 6.5 2026-09-04 Onyx 4.6.6 fails to properly restrict access to custom tool credentials stored in custom_headers, allowing any authenticated user to read admin-defined API keys. Attackers …
CVE-2026-85699 HIGH 7.5 2026-09-04 jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect …
CVE-2026-85698 MEDIUM 5.5 2026-09-04 Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attacker-controlled cell-count field without bounds valida…
CVE-2026-85697 MEDIUM 6.5 2026-09-04 Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can…
CVE-2026-85696 CRITICAL 9.8 2026-09-04 SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper esc…
CVE-2026-85695 CRITICAL 9.4 2026-09-04 FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and p…
CVE-2026-85694 HIGH 8.1 2026-09-04 LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from w…
CVE-2026-85693 MEDIUM 6.5 2026-09-04 Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other us…
CVE-2026-85692 MEDIUM 6.5 2026-09-04 Nightingale (n9e), as of commit 8362cbe (main branch, confirmed 2026-08-27), contains a server-side request forgery vulnerability in the isPublicIP function in aiagent/tool…
CVE-2026-85691 HIGH 7.5 2026-09-04 MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers…
CVE-2026-85690 HIGH 7.8 2026-09-04 Plandex 2.2.1 contains a path traversal vulnerability in the ApplyFiles function that allows attackers to write files outside the project directory. Attackers can influence…
CVE-2026-85689 MEDIUM 6.5 2026-09-04 llmware 0.4.6 contains an SQL injection vulnerability in the collection-database layer (llmware/resources.py) where filter and lookup values are directly string-interpolate…
CVE-2026-85688 CRITICAL 9.8 2026-09-04 TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and …
CVE-2026-85687 HIGH 7.5 2026-09-04 surya 0.22.1 screenshot server contains an unauthenticated arbitrary file read vulnerability in the /info, /page, and /process routes that accept raw file_path parameters. …
CVE-2026-85686 HIGH 7.5 2026-09-04 ms-swift 4.5.2 contains a server-side request forgery vulnerability in the swift deploy OpenAI-compatible API that fetches multimodal media URLs without validation or redir…
CVE-2026-85685 HIGH 7.5 2026-09-04 AgentScope through 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill that copies arbitrary server directories into the agent workspace via an …
CVE-2026-85684 CRITICAL 9.1 2026-09-04 marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attac…
CVE-2026-85676 MEDIUM 4.3 2026-09-04 Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement. Attack…
CVE-2026-85675 HIGH 7.5 2026-09-04 OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no scheme, …