CVE ID :CVE-2026-71476 Published : 2026年8月6日 22:18 | 1 小时,34 分钟 ago Description :Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP…
CVE-2026-71445 – Authenticated Reflected Cross-Site Scripting in Tag Error Responses in ail-framework
CVE ID :CVE-2026-71445 Published : 2026年8月6日 22:18 | 1 小时,34 分钟 ago Description :AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occurred while processing a tag operation,…
CVE-2026-70638 – llama.cpp b1886–b7445 Integer Overflow via new_1batch() in llama-android.cpp
CVE ID :CVE-2026-70638 Published : 2026年8月6日 22:18 | 1 小时,34 分钟 ago Description :llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id)…
CVE-2026-70636 – Flowise 3.1.4 Authentication Bypass via OAuth2 Credential Refresh Endpoint
CVE ID :CVE-2026-70636 Published : 2026年8月6日 22:18 | 1 小时,34 分钟 ago Description :Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting…
CVE-2026-70634 – TimescaleDB 2.29.1 Out-of-Bounds Read Information Disclosure via Dictionary Compression Reverse Iterator
CVE ID :CVE-2026-70634 Published : 2026年8月6日 22:18 | 1 小时,34 分钟 ago Description :TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward…
CVE-2026-67531 – FrontMCP: CodeCall sandbox escape -> host RCE via live Zod schema exposure by getTool
CVE ID :CVE-2026-67531 Published : Aug. 6, 2026, 12:16 a.m. | 1 hour, 33 minutes ago Description :FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool…
CVE-2026-19024 – HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message
CVE ID :CVE-2026-19024 Published : Aug. 5, 2026, 11:16 p.m. | 33 minutes ago Description :NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.1.1 allows attackers to cause a denial of service via…
CVE-2026-71320 – Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
CVE ID :CVE-2026-71320 Published : Aug. 5, 2026, 10:17 p.m. | 1 hour, 33 minutes ago Description :Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker…
CVE-2026-71319 – Nuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code Execution
CVE ID :CVE-2026-71319 Published : Aug. 5, 2026, 10:17 p.m. | 1 hour, 33 minutes ago Description :Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only)…
CVE-2026-71315 – Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
CVE ID :CVE-2026-71315 Published : Aug. 5, 2026, 9:16 p.m. | 2 hours, 33 minutes ago Description :Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules…