7.8
CVE-2025-33247 -
NVIDIA Megatron LM contains a vulnerability in quantization configuration loading, which could allow remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
5.9
CVE-2025-33242 - MCU Registry Modification Leading to Denial of Service and Data Tampering in NVIDIA B300
NVIDIA B300 MCU contains a vulnerability in the CX8 MCU that could allow a malicious actor to modify unsupported registries, causing a bad state. A successful exploit of this vulnerability might lead to denial of service and data tampering.
6.8
CVE-2025-33216 - Buffer Size Miscalculation in NVIDIA SNAPβ4 Container Leading to Denial of Service
NVIDIA SNAP-4 Container contains a vulnerability in the configuration interface where an attacker on a VM may cause an incorrect calculation of buffer size by sending crafted configurations. A successful exploit of this vulnerability may lead to crash of the SNAP service, causing denial of service β¦
6.8
CVE-2025-33215 - VIRTIO-BLK Out-of-Range Pointer Offsets Cause Storage Denial of Service in NVIDIA SNAP-4 Container
NVIDIA SNAP-4 Container contains a vulnerability in the VIRTIO-BLK component where a malicious guest VM may cause use of out-of-range pointer offset by sending crafted messages. A successful exploit of this vulnerability may lead to a denial of service of the DPA and impact the availability of storβ¦
6.3
CVE-2026-21790 - HCL Traveler is susceptible to a weak default HTTP header validation vulnerability
HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could allow an attacker to bypass additional authentication checks.
4.3
CVE-2026-21783 - HCL Traveler is affected by sensitive information disclosure
HCL Traveler is affected by sensitive information disclosure.Β The application generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces.Β Attackers could exploit this inβ¦
5.6
CVE-2026-33412 - Vim affected by Command injection via newline in glob()
Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n) in a pattern passed to glob(), an attacker may be able to execute arbitrary shell commands. This β¦
7.1
CVE-2026-33353 - Soft Serve: Authenticated repo import can clone server-local private repositories
Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allows any authenticated SSH user to clone a server-local Git repository, including another user's private repo, into a new repository they control. This β¦
5.9
CVE-2026-33349 - fast-xml-parser: Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluatiβ¦
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.0-beta.3 to before version 5.5.7, the DocTypeReader in fast-xml-parser uses JavaScript truthy checks to evaluate maxEntityCount and maxEntitySize configuration limits. When a deveβ¦
6.5
CVE-2026-33345 - solidtime vulnerable to IDOR in private projects
solidtime is an open-source time-tracking app. Prior to version 0.11.6, the project detail endpoint GET /api/v1/organizations/{org}/projects/{project} allows any authenticated Employee to access any project in the organization by UUID, including private projects they are not a member of. The index(β¦