| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-69262 | Hig | 0.46 | 8.1 | 0.01 | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), so possession of either permission was sufficient to reach… | ||
| CVE-2026-69259 | Hig | 0.50 | 8.8 | 0.01 | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-controlled additionalConfig and spread it… | ||
| CVE-2026-69258 | Cri | 0.52 | 9.1 | 0.01 | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig and flowData objects in… | ||
| CVE-2026-69257 | Hig | 0.49 | 8.6 | 0.00 | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.254.169.254 before checking them against… | ||
| CVE-2026-69256 | Hig | 0.50 | 8.8 | 0.01 | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; although a denylist blocked dangerous Python constructs, pandas.read_pickle() could… | ||
| CVE-2026-69255 | Hig | 0.50 | 8.8 | 0.01 | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').pop() and interpolated it directly into… | ||
| CVE-2026-64634 | Hig | 0.55 | — | 0.00 | Aug 4, 2026 | A vulnerability allowing local privilege escalation to the Reporter service context. | ||
| CVE-2026-64633 | Cri | 0.65 | — | 0.01 | Aug 4, 2026 | A vulnerability allowing remote unauthenticated code execution on the agent host. | ||
| CVE-2026-64631 | Hig | 0.56 | — | 0.00 | Aug 4, 2026 | A vulnerability allowing a low-privileged user to inject SQL and extract database contents. | ||
| CVE-2026-64630 | Med | 0.34 | — | 0.00 | Aug 4, 2026 | A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link. | ||
| CVE-2026-63456 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2026 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify… | ||
| CVE-2026-63455 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2026 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify… | ||
| CVE-2026-58075 | Hig | 0.57 | — | 0.00 | Aug 4, 2026 | A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally. | ||
| CVE-2026-58074 | — | Hig | 0.56 | — | 0.01 | Aug 4, 2026 | A vulnerability allowing a high-privileged user to execute arbitrary code on the server. | |
| CVE-2026-58073 | Cri | 0.62 | — | 0.00 | Aug 4, 2026 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials. | ||
| CVE-2026-58072 | Cri | 0.59 | — | 0.01 | Aug 4, 2026 | A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution. | ||
| CVE-2026-58071 | Hig | 0.53 | — | 0.00 | Aug 4, 2026 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins. | ||
| CVE-2026-58067 | Hig | 0.57 | — | 0.00 | Aug 4, 2026 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service. | ||
| CVE-2026-56848 | Hig | 0.49 | 7.5 | 0.00 | Aug 4, 2026 | A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**. | ||
| CVE-2026-48121 | Med | 0.37 | 6.7 | 0.00 | Aug 4, 2026 | @langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and below are vulnerable to NoSQL injection: checkpoint identifiers (thread_id, checkpoint_ns, checkpoint_id) from config.configurable are… | ||
| CVE-2026-18787 | Hig | 0.57 | 8.8 | 0.03 | Aug 4, 2026 | A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the component RPC Endpoint. The manipulation of the argument args.id leads to command injection. The attack is possible to… | ||
| CVE-2026-18785 | Med | 0.34 | 5.3 | 0.00 | Aug 4, 2026 | A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a manipulation can lead to use after free. It is possible to… | ||
| CVE-2026-18784 | Med | 0.34 | 5.3 | 0.00 | Aug 4, 2026 | A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute of the file src/client/ua_client_highlevel.c. Performing a manipulation results in heap-based buffer overflow. Attacking locally is a requirement. The exploit… | ||
| CVE-2026-18775 | Med | 0.41 | 6.3 | 0.00 | Aug 4, 2026 | A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/browser_tool.py of the component Browser Tooling. Such manipulation leads to server-side request forgery. The attack may be… | ||
| CVE-2026-18774 | Med | 0.41 | 6.3 | 0.00 | Aug 4, 2026 | A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image Generation Provider. This manipulation causes server-side request forgery. The attack may be initiated… | ||
| CVE-2026-15920 | Med | 0.33 | 6.1 | 0.00 | Aug 4, 2026 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is displayed as a link on… | ||
| CVE-2026-15830 | Med | 0.28 | 5.3 | 0.01 | Aug 4, 2026 | An issue was discovered in Django 6.0 before 6.0.9 and 5.2 before 5.2.18. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary… | ||
| CVE-2026-15337 | Med | 0.27 | 5.3 | 0.01 | Aug 4, 2026 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which are retained as keys in an in-memory cache and… | ||
| CVE-2026-15314 | Hig | 0.49 | 7.5 | 0.01 | Aug 4, 2026 | Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing the web service… | ||
| CVE-2026-15307 | Hig | 0.50 | 8.8 | 0.01 | Aug 4, 2026 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value used in a spatial lookup against a… | ||
| CVE-2025-29296 | Cri | 0.64 | 9.8 | 0.02 | Aug 4, 2026 | H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100R002 and H3C MC102G HM1A0V200R010 contain multiple command injection vulnerabilities in the /api/esps… | ||
| CVE-2026-69254 | Hig | 0.50 | 8.8 | 0.01 | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-provided nodeVMOptions and merged them over the default NodeVM security settings in packages/components/src/utils.ts. An authenticated… | ||
| CVE-2026-69253 | Hig | 0.50 | 8.8 | 0.01 | Aug 4, 2026 | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and ExecuteFlow — ran code in the in-process vm2 sandbox. To build that code, they… | ||
| CVE-2026-69252 | Hig | 0.50 | 8.8 | 0.01 | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only by the feat:files feature gate and did not enforce checkPermission on GET or DELETE. A low-privileged authenticated API key with… | ||
| CVE-2026-69110 | Cri | 0.52 | 9.1 | 0.01 | Aug 4, 2026 | OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints.… | ||
| CVE-2026-69100 | Hig | 0.50 | 8.8 | 0.01 | Aug 4, 2026 | LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or… | ||
| CVE-2026-69098 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2026 | kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to… | ||
| CVE-2026-25292 | Hig | 0.49 | 7.6 | 0.00 | Aug 4, 2026 | Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration. | ||
| CVE-2026-25289 | Cri | 0.62 | 9.6 | 0.00 | Aug 4, 2026 | Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values. | ||
| CVE-2026-25288 | Hig | 0.48 | 7.4 | 0.00 | Aug 4, 2026 | Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size. | ||
| CVE-2026-24084 | Hig | 0.49 | 7.5 | 0.00 | Aug 4, 2026 | Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities. | ||
| CVE-2026-24083 | Hig | 0.51 | 7.8 | 0.00 | Aug 4, 2026 | Memory Corruption while processing IOCTL device driver requests with invalid arguments. | ||
| CVE-2026-24080 | Hig | 0.51 | 7.8 | 0.00 | Aug 4, 2026 | Memory Corruption when handling malformed request parameters in the fingerprint TA. | ||
| CVE-2026-24079 | Hig | 0.53 | 8.1 | 0.00 | Aug 4, 2026 | Cryptographic Issue while processing registration requests with malformed or missing authentication parameters. | ||
| CVE-2026-24078 | Med | 0.42 | 6.5 | 0.00 | Aug 4, 2026 | Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. | ||
| CVE-2026-24077 | Med | 0.42 | 6.5 | 0.00 | Aug 4, 2026 | Information Disclosure when processing wireless network channel switch information with improperly formatted length fields. | ||
| CVE-2026-24076 | Med | 0.44 | 6.7 | 0.00 | Aug 4, 2026 | Memory Corruption when processing registry values with incorrect types using a direct query method. | ||
| CVE-2026-21366 | Hig | 0.51 | 7.8 | 0.00 | Aug 4, 2026 | Memory corruption while processing a packet with a size close to the maximum allowed value. | ||
| CVE-2026-18801 | Cri | 0.53 | — | 0.00 | Aug 4, 2026 | OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution values. An attacker who can create or update a customer can store a malicious value in the usageAttribution.key or usageAttribution.subjectKeys fields. When… | ||
| CVE-2026-18773 | Med | 0.41 | 6.3 | 0.00 | Aug 4, 2026 | A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The attack can be launched… |
- risk 0.46cvss 8.1epss 0.01
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), so possession of either permission was sufficient to reach…
- risk 0.50cvss 8.8epss 0.01
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-controlled additionalConfig and spread it…
- risk 0.52cvss 9.1epss 0.01
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig and flowData objects in…
- risk 0.49cvss 8.6epss 0.00
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.254.169.254 before checking them against…
- risk 0.50cvss 8.8epss 0.01
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; although a denylist blocked dangerous Python constructs, pandas.read_pickle() could…
- risk 0.50cvss 8.8epss 0.01
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').pop() and interpolated it directly into…
- risk 0.55cvss —epss 0.00
A vulnerability allowing local privilege escalation to the Reporter service context.
- risk 0.65cvss —epss 0.01
A vulnerability allowing remote unauthenticated code execution on the agent host.
- risk 0.56cvss —epss 0.00
A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
- risk 0.34cvss —epss 0.00
A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.
- risk 0.64cvss 9.8epss 0.01
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify…
- risk 0.64cvss 9.8epss 0.01
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify…
- risk 0.57cvss —epss 0.00
A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.
- risk 0.56cvss —epss 0.01
A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
- risk 0.62cvss —epss 0.00
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.
- risk 0.59cvss —epss 0.01
A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution.
- risk 0.53cvss —epss 0.00
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins.
- risk 0.57cvss —epss 0.00
A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.
- risk 0.49cvss 7.5epss 0.00
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
- risk 0.37cvss 6.7epss 0.00
@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and below are vulnerable to NoSQL injection: checkpoint identifiers (thread_id, checkpoint_ns, checkpoint_id) from config.configurable are…
- risk 0.57cvss 8.8epss 0.03
A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the component RPC Endpoint. The manipulation of the argument args.id leads to command injection. The attack is possible to…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the file examples/custom_datatype/client_types_custom.c. Executing a manipulation can lead to use after free. It is possible to…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute of the file src/client/ua_client_highlevel.c. Performing a manipulation results in heap-based buffer overflow. Attacking locally is a requirement. The exploit…
- risk 0.41cvss 6.3epss 0.00
A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/browser_tool.py of the component Browser Tooling. Such manipulation leads to server-side request forgery. The attack may be…
- risk 0.41cvss 6.3epss 0.00
A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image Generation Provider. This manipulation causes server-side request forgery. The attack may be initiated…
- risk 0.33cvss 6.1epss 0.00
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is displayed as a link on…
- risk 0.28cvss 5.3epss 0.01
An issue was discovered in Django 6.0 before 6.0.9 and 5.2 before 5.2.18. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potential denial-of-service when parsing deeply nested `GEOMETRYCOLLECTION` objects supplied as well-known text (WKT), well-known binary…
- risk 0.27cvss 5.3epss 0.01
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential denial-of-service attack when given many distinct, very long language codes, which are retained as keys in an in-memory cache and…
- risk 0.49cvss 7.5epss 0.01
Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing the web service…
- risk 0.50cvss 8.8epss 0.01
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by passing it to the `django.contrib.gis.gdal.GDALRaster` constructor. Any value used in a spatial lookup against a…
- risk 0.64cvss 9.8epss 0.02
H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100R002 and H3C MC102G HM1A0V200R010 contain multiple command injection vulnerabilities in the /api/esps…
- risk 0.50cvss 8.8epss 0.01
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-provided nodeVMOptions and merged them over the default NodeVM security settings in packages/components/src/utils.ts. An authenticated…
- risk 0.50cvss 8.8epss 0.01
Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and ExecuteFlow — ran code in the in-process vm2 sandbox. To build that code, they…
- risk 0.50cvss 8.8epss 0.01
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only by the feat:files feature gate and did not enforce checkPermission on GET or DELETE. A low-privileged authenticated API key with…
- risk 0.52cvss 9.1epss 0.01
OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints.…
- risk 0.50cvss 8.8epss 0.01
LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or…
- risk 0.64cvss 9.8epss 0.01
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to…
- risk 0.49cvss 7.6epss 0.00
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
- risk 0.62cvss 9.6epss 0.00
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
- risk 0.48cvss 7.4epss 0.00
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
- risk 0.49cvss 7.5epss 0.00
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
- risk 0.51cvss 7.8epss 0.00
Memory Corruption when handling malformed request parameters in the fingerprint TA.
- risk 0.53cvss 8.1epss 0.00
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
- risk 0.42cvss 6.5epss 0.00
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
- risk 0.42cvss 6.5epss 0.00
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
- risk 0.44cvss 6.7epss 0.00
Memory Corruption when processing registry values with incorrect types using a direct query method.
- risk 0.51cvss 7.8epss 0.00
Memory corruption while processing a packet with a size close to the maximum allowed value.
- risk 0.53cvss —epss 0.00
OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution values. An attacker who can create or update a customer can store a malicious value in the usageAttribution.key or usageAttribution.subjectKeys fields. When…
- risk 0.41cvss 6.3epss 0.00
A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The attack can be launched…