Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54367
Total
4306
Critical
16164
High
15850
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-100383 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Cross-Site Scripting (XSS). This … | Sep 25, 2026 |
| CVE-2026-100382 | UNKNOWN | — | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection. … | Sep 25, 2026 |
| CVE-2026-100381 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - UploadWizard Extension allows Cross-Site Scripting (XSS). This … | Sep 25, 2026 |
| CVE-2026-9313 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 25, 2026 |
| CVE-2026-96879 | UNKNOWN | — | Improper removal of sensitive information before storage or transfer vulnerability in Wikimedia Foundation's Mediawiki - FlaggedRevs extension through 1.46.0. | Sep 25, 2026 |
| CVE-2026-91769 | MEDIUM | 4.3 | PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires … | Sep 25, 2026 |
| CVE-2026-91767 | MEDIUM | 6.5 | php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer … | Sep 25, 2026 |
| CVE-2026-91766 | MEDIUM | 5.9 | When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a … | Sep 25, 2026 |
| CVE-2026-91765 | HIGH | 7.5 | cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing … | Sep 25, 2026 |
| CVE-2026-6103 | MEDIUM | 4.3 | phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and … | Sep 25, 2026 |
| CVE-2026-57864 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 25, 2026 |
| CVE-2026-57443 | HIGH | 7.5 | SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1, the AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) exposes the … | Sep 25, 2026 |
| CVE-2026-17545 | UNKNOWN | — | On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, … | Sep 25, 2026 |
| CVE-2026-10758 | HIGH | 7.5 | Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via … | Sep 25, 2026 |
| CVE-2026-100417 | LOW | 3.1 | RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from … | Sep 25, 2026 |
| CVE-2026-100391 | HIGH | 8.2 | MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query … | Sep 25, 2026 |
| CVE-2026-100390 | HIGH | 7.4 | Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can … | Sep 25, 2026 |
| CVE-2026-100389 | HIGH | 8.1 | GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated … | Sep 25, 2026 |
| CVE-2026-100388 | MEDIUM | 5.4 | RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS. … | Sep 25, 2026 |
| CVE-2026-100387 | HIGH | 8.1 | pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers … | Sep 25, 2026 |
| CVE-2026-100380 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Site Scripting (XSS). This … | Sep 25, 2026 |
| CVE-2026-100379 | UNKNOWN | — | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP Cookies. This issue affects Wikipedia Android App: … | Sep 25, 2026 |
| CVE-2026-100378 | UNKNOWN | — | Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - Translate Extension: … | Sep 25, 2026 |
| CVE-2026-100377 | UNKNOWN | — | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Excavation. This issue affects Mediawiki - WikiLambda Extension: … | Sep 25, 2026 |
| CVE-2026-100376 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Cross-Site Scripting (XSS). This … | Sep 25, 2026 |