HIGH
NVDSUPPLY-CHAINCVE-2026-49119
2026-07-01
Gradio before 6.16.0 contains a path traversal vulnerability that allows unauthenticated attackers to escape the configured root directory.
HIGH
NVDSUPPLY-CHAINCVE-2026-57516
2026-07-01
An unsafe deserialization vulnerability in the WebDataset reader of Ray allows attackers to achieve remote code execution.
HIGH
NVDSUPPLY-CHAINCVE-2026-24264
2026-07-01
NVIDIA Triton Inference Server for Linux contains a vulnerability that could lead to denial of service.
HIGH
NVDSUPPLY-CHAINCVE-2026-24266
2026-07-01
NVIDIA Triton Inference Server for Linux contains a vulnerability that can be exploited by an attacker, potentially leading to denial of service.
2026-07-01
OpenClaw MCP SSE redirects could forward Authorization headers, potentially executing or persisting actions beyond intended authorization.
HIGH
GHSASUPPLY-CHAINCVE-2026-50143
2026-07-01
An attacker can exfiltrate the victim's Apify API token by crafting a malicious Actor with a specific webServerMcpPath value.
HIGH
GHSASUPPLY-CHAINCVE-2026-49857
2026-07-01
A protection bypass vulnerability in auth-fetch-mcp allows attackers to reach loopback services that should be blocked.