Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54367
Total
4306
Critical
16164
High
15850
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-100714 | CRITICAL | 9.1 | Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, … | Sep 26, 2026 |
| CVE-2026-100713 | HIGH | 7.8 | Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cron (lib/Froxlor/Cron/System/SshKeys.php, SshKeys::generateFiles). The containment/symlink validation performed by FileDir::makeCorrectDir()/makeCorrectFile() … | Sep 26, 2026 |
| CVE-2026-100712 | MEDIUM | 6.5 | froxlor through 2.3.10 disables a user's two-factor authentication immediately upon an unauthenticated-triggerable GET request to the 2FA management page (e.g. /customer_index.php?page=2fa&action=delete), with no confirmation, re-authentication, … | Sep 26, 2026 |
| CVE-2026-100711 | HIGH | 7.5 | froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked … | Sep 26, 2026 |
| CVE-2026-100710 | MEDIUM | 4.9 | Froxlor through 2.3.10 does not filter sensitive columns from API responses: Domains::get(), Domains::listing(), SubDomains::get(), and the admin branch of SubDomains::listing() perform a wildcard SELECT over … | Sep 26, 2026 |
| CVE-2026-100709 | HIGH | 7.5 | Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the account namespace, and the remembered-token lookup during login is … | Sep 26, 2026 |
| CVE-2026-100708 | HIGH | 7.1 | Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key content — verbatim in the JSON responses of the Certificates.get … | Sep 26, 2026 |
| CVE-2026-100707 | HIGH | 7.7 | Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespaced Policy resources due to inconsistent path interpretation between validation and … | Sep 26, 2026 |
| CVE-2026-100706 | CRITICAL | 9.9 | kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects … | Sep 26, 2026 |
| CVE-2026-100705 | HIGH | 7.6 | Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (169.254.169.254, 169.254.169.253, metadata.google.internal, 127.0.0.0/8, ::1/128) and the scoped-token control were wired only … | Sep 26, 2026 |
| CVE-2026-100704 | HIGH | 7.7 | Kyverno is a policy engine for Kubernetes. In versions 1.14.0 through 1.19.0, the ImageValidatingPolicy (policies.kyverno.io/v1beta1) evaluator never reads the spec.images and spec.allowedValues fields of a … | Sep 26, 2026 |
| CVE-2026-100703 | HIGH | 7.7 | Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it to the policy's namespace, unlike the sibling libraries (resource.Lib, … | Sep 26, 2026 |
| CVE-2026-100702 | MEDIUM | 5.9 | Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, allowing attackers to cause stack exhaustion. … | Sep 26, 2026 |
| CVE-2026-100701 | MEDIUM | 5.9 | Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache that is keyed only by the DNS host, while each cache entry also stores the … | Sep 26, 2026 |
| CVE-2026-100700 | HIGH | 7.5 | nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted … | Sep 26, 2026 |
| CVE-2026-100699 | MEDIUM | 5.3 | Nodemailer is a Node.js email-sending library. In versions >= 9.1.0 and < 10.0.9, the address parser (src/addressparser) mishandles addresses whose local-part is a quoted string … | Sep 26, 2026 |
| CVE-2026-100698 | MEDIUM | 5.8 | Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/functions.inc.php. The port capture group requires pure digits anchored to … | Sep 26, 2026 |
| CVE-2026-100697 | HIGH | 8.6 | Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated … | Sep 26, 2026 |
| CVE-2026-100696 | MEDIUM | 5.8 | Adminer 4.16.0 through 6.0.1 contain a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the optional Elasticsearch driver (plugins/drivers/elastic.php), fixed in 6.0.2. Because adminer/include/auth.inc.php invokes Driver::connect() … | Sep 26, 2026 |
| CVE-2026-100695 | MEDIUM | 6.1 | Adminer before 6.0.2 contains a cross-site scripting vulnerability where the CONNECTION_ID() database result is interpolated into JavaScript without proper escaping, allowing a malicious database server … | Sep 26, 2026 |
| CVE-2026-100694 | MEDIUM | 6.1 | Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type are rendered without escaping raw … | Sep 26, 2026 |
| CVE-2026-100693 | HIGH | 8.4 | Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can … | Sep 26, 2026 |
| CVE-2026-100692 | HIGH | 7.5 | Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount root itself, so a … | Sep 26, 2026 |
| CVE-2026-100691 | MEDIUM | 5.4 | Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not escape the `lineAnchors` option before passing it to Chroma, … | Sep 26, 2026 |
| CVE-2026-100690 | HIGH | 7.5 | Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project … | Sep 26, 2026 |