feed · advisories

Security Advisories

Recent CVEs from the NVD, ranked by CVSS score. High and critical severity tracked by default.

— · — · CVSS 9.8 · Aug 8

The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action…

NVD detail →
apache · nifi · CVSS 9.8 · Aug 3

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that…

NVD detail →
— · — · CVSS 9.8 · Aug 3

A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command…

NVD detail →
— · — · CVSS 9.8 · Aug 3

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the…

NVD detail →
— · — · CVSS 9.8 · Aug 3

A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Executing a manipulation of the argument…

NVD detail →
dell · virtual storage integrator · CVSS 9.1 · Aug 6

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading…

NVD detail →
eclipse · jetty · CVSS 9.1 · Aug 4

In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be…

NVD detail →
apache · nifi · CVSS 9.1 · Aug 3

Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied…

NVD detail →
— · — · CVSS 9.1 · Aug 3

OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system commands by…

NVD detail →
microsoft · azure sql managed instance · CVSS 8.7 · Aug 7

Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.

NVD detail →
langflow · langflow · CVSS 8.5 · Aug 5

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.

NVD detail →
langflow · langflow · CVSS 8.5 · Aug 5

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary…

NVD detail →
eclipse · milo · CVSS 8.2 · Aug 4

In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running configuration through `copy()`, sessions receive no…

NVD detail →
langflow · langflow · CVSS 8.1 · Aug 5

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated…

NVD detail →
— · — · CVSS 8.1 · Aug 3

OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a…

NVD detail →
n-able · n-central · CVSS 8.1 · Aug 2

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

NVD detail →
— · — · CVSS 7.8 · Aug 3

A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program Files (x86)\Razer\RzUpdateEngineService\RzUpdateService.exe of the component Named Pipe…

NVD detail →
dell · openmanage server administrator · CVSS 7.7 · Aug 7

Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized…

NVD detail →
langflow · langflow · CVSS 7.7 · Aug 5

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote attacker to traverse directories on the system. An attacker could…

NVD detail →
microsoft · edge · CVSS 7.7 · Aug 4

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

NVD detail →