Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54305
Total
4306
Critical
16147
High
15838
Medium
CVE ID Severity Score Description Published
CVE-2026-100867 LOW 3.3 spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before rendering them in the zsh prompt. Attackers can embed ANSI/OSC escape … Sep 27, 2026
CVE-2026-100866 LOW 3.3 onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape … Sep 27, 2026
CVE-2026-97165 UNKNOWN — Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” parameter is base64-decoded and written to … Sep 27, 2026
CVE-2026-97164 UNKNOWN — Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extension < 6.5.0 - Using the `images` parameter of … Sep 27, 2026
CVE-2026-100749 UNKNOWN — Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only orphaned file entries and shopping carts that … Sep 27, 2026
CVE-2026-100748 UNKNOWN — Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0 Sep 27, 2026
CVE-2026-100747 UNKNOWN — Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF token check, a … Sep 27, 2026
CVE-2026-94417 UNKNOWN — When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL skips the CRL check for any peer certificate … Sep 27, 2026
CVE-2026-93304 UNKNOWN — A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has been derived at that point, so … Sep 27, 2026
CVE-2026-93302 UNKNOWN — MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any that enable the macro WOLFSSL_TRUST_PEER_CERT and load CA … Sep 27, 2026
CVE-2026-89136 UNKNOWN — When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could accept an unsolicited server_cert_type=RawPublicKey which allowed … Sep 27, 2026
CVE-2026-89135 UNKNOWN — A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certificate validation in every type-blind sibling consumer (native TLS, OCSP, … Sep 27, 2026
CVE-2026-89134 UNKNOWN — A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN dNSName name-constraint check. The CN-as-DNS fallback … Sep 27, 2026
CVE-2026-89133 UNKNOWN — wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly enforce NameConstraints extensions when there is … Sep 27, 2026
CVE-2026-89102 UNKNOWN — In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response stapling, which can lead to certificate forgery. … Sep 27, 2026
CVE-2026-15442 UNKNOWN — In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS shutdown which could lead … Sep 27, 2026
CVE-2026-94419 UNKNOWN — Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of the form {row, index, hash(sessionID)} into the process-global SessionCache, and ClientSessionToSession() … Sep 27, 2026
CVE-2026-94418 UNKNOWN — Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse to keep peak memory down, then merges the two results, but it merged … Sep 27, 2026
CVE-2026-100741 CRITICAL 9.8 Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a remote, unauthenticated attacker to run … Sep 27, 2026
CVE-2026-97319 MEDIUM 6.8 The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribute before outputting it in a page, which … Sep 27, 2026
CVE-2026-97227 MEDIUM 5.9 The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a … Sep 27, 2026
CVE-2026-96899 MEDIUM 6.8 The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it … Sep 27, 2026
CVE-2026-96897 MEDIUM 5.3 The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions that is available to logged-out … Sep 27, 2026
CVE-2026-96896 HIGH 7.2 The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowing … Sep 27, 2026
CVE-2026-96895 MEDIUM 6.8 The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when … Sep 27, 2026