Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54305
Total
4306
Critical
16147
High
15838
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-100898 | MEDIUM | 6.3 | A vulnerability was detected in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/2.0.0-beta1. This affects the function whereRaw of the file app/Filament/Widgets/Timesheet/ActivitiesReport.php of the component Timesheet Dashboard. Performing a manipulation … | Sep 28, 2026 |
| CVE-2026-100897 | MEDIUM | 5.5 | A security vulnerability has been detected in fuzui StudentInfo up to fcc42a639ec7cef620651bfd0f07ebb660529e3f. The impacted element is an unknown function of the file /StudentInfo/StudentHandler/moditypasswordstu of the … | Sep 28, 2026 |
| CVE-2026-100896 | CRITICAL | 9.9 | A weakness has been identified in TOTOLINK N150RT 3.4.0-B20201030. The affected element is the function system of the file /boafrm/formWlSiteSurvey of the component Web Management … | Sep 28, 2026 |
| CVE-2026-100895 | MEDIUM | 5.3 | A security flaw has been discovered in Trusted Domain Project OpenARC up to 1.0.0.Beta1. Impacted is the function arc_parse_canon_t in the library libopenarc/arc-canon.c of the … | Sep 28, 2026 |
| CVE-2026-100894 | MEDIUM | 6.3 | A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This issue affects some unknown processing of the file updateguest.php. The manipulation of the argument … | Sep 28, 2026 |
| CVE-2026-100893 | HIGH | 7.3 | A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse … | Sep 28, 2026 |
| CVE-2026-100892 | MEDIUM | 5.3 | A vulnerability was found in aligungr UERANSIM up to 3.3.0. This affects the function ULInformationTransfer of the file src/gnb/rrc/handler.cpp of the component nr-gnb. Performing a … | Sep 28, 2026 |
| CVE-2026-100891 | HIGH | 7.3 | A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c … | Sep 28, 2026 |
| CVE-2026-100890 | MEDIUM | 5.3 | A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_spf_ipv6_explode in the library libopendmarc/opendmarc_spf.c … | Sep 28, 2026 |
| CVE-2026-100889 | HIGH | 7.3 | A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. … | Sep 28, 2026 |
| CVE-2026-100888 | HIGH | 7.3 | A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the function dkim_canon_selecthdrs of the file libopendkim/dkim-canon.c of the component … | Sep 28, 2026 |
| CVE-2026-100887 | MEDIUM | 6.3 | A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. The impacted element is the function order_by of the file DB_query_builder.php of the … | Sep 28, 2026 |
| CVE-2026-96284 | LOW | 2.5 | A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in … | Sep 27, 2026 |
| CVE-2026-100886 | CRITICAL | 10.0 | A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such … | Sep 27, 2026 |
| CVE-2026-100885 | HIGH | 7.3 | A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. … | Sep 27, 2026 |
| CVE-2026-100884 | MEDIUM | 4.3 | A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component … | Sep 27, 2026 |
| CVE-2026-100883 | MEDIUM | 6.3 | A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the file packages/Webkul/Admin/src/Config/acl.php. Executing a manipulation … | Sep 27, 2026 |
| CVE-2026-96283 | LOW | 3.3 | By calling org.freedesktop.Flatpak.SystemHelper.CancelPull on another user's pull, the pull is not actually cancelled but removed from internal tracking, making it impossible for the owning user … | Sep 27, 2026 |
| CVE-2026-96282 | LOW | 3.1 | A malicious Flatpak extension can probe the host filesystem to determine what files and directories exist at arbitrary paths, and host directory listings can be … | Sep 27, 2026 |
| CVE-2026-100882 | LOW | 2.4 | A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the component Admin Settings Endpoint. … | Sep 27, 2026 |
| CVE-2026-100881 | LOW | 2.6 | A security vulnerability has been detected in zhistaredu StarTraining up to 3.8.1. This issue affects some unknown processing of the file application.yml. Such manipulation of … | Sep 27, 2026 |
| CVE-2026-96281 | MEDIUM | 6.2 | On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older version by removing the … | Sep 27, 2026 |
| CVE-2026-96280 | HIGH | 7.5 | The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), … | Sep 27, 2026 |
| CVE-2026-101090 | CRITICAL | 9.8 | Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the … | Sep 27, 2026 |
| CVE-2026-101089 | LOW | 3.1 | Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the bcrypt-hashed password field of authenticated users. Attackers can extract … | Sep 27, 2026 |