NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-93952 VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and... 2026-09-22 10.0 NETWORK CRITICAL NVD
CVE-2026-76974 SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker could craft a malicious link that, when ... 2026-09-22 5.3 NETWORK MEDIUM NVD
CVE-2026-94627 vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID... 2026-09-21 7.5 NETWORK HIGH NVD
CVE-2026-94626 vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to all... 2026-09-21 7.5 NETWORK HIGH NVD
CVE-2026-94625 vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeh... 2026-09-21 5.3 NETWORK MEDIUM NVD
CVE-2026-94624 vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec ... 2026-09-21 7.5 NETWORK HIGH NVD
CVE-2026-94623 vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate b... 2026-09-21 7.5 NETWORK HIGH NVD
CVE-2026-94622 vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated depl... 2026-09-21 7.5 NETWORK HIGH NVD
CVE-2026-61541 Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests content from an untrusted server... 2026-09-21 6.9 NETWORK MEDIUM NVD
CVE-2026-17054 The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-processor in esp_hosted_event_task().... 2026-09-21 5.3 ADJACENT_NETWORK MEDIUM NVD
CVE-2026-15890 The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead_get_nonce() in subsys/secure_... 2026-09-21 5.3 LOCAL MEDIUM NVD
CVE-2026-94572 In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The v... 2026-09-21 9.4 NETWORK CRITICAL NVD
CVE-2026-94571 In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fi... 2026-09-21 9.4 NETWORK CRITICAL NVD
CVE-2026-93433 A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specially crafted SCSI (Small Comput... 2026-09-21 5.5 LOCAL MEDIUM NVD
CVE-2026-73553 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, When ignore_path_... 2026-09-21 7.5 NETWORK HIGH NVD