Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54449
Total
4308
Critical
16178
High
15893
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-45236 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 25, 2026 |
| CVE-2026-45235 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 25, 2026 |
| CVE-2026-45234 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 25, 2026 |
| CVE-2026-100502 | MEDIUM | 5.0 | Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrary … | Sep 25, 2026 |
| CVE-2026-100501 | MEDIUM | 6.5 | Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attackers to brute-force the … | Sep 25, 2026 |
| CVE-2026-100419 | HIGH | 7.0 | gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symlink … | Sep 25, 2026 |
| CVE-2026-100418 | MEDIUM | 5.3 | Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that returns the entire configuration object without field redaction. Attackers can … | Sep 25, 2026 |
| CVE-2026-100383 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Cross-Site Scripting (XSS). This … | Sep 25, 2026 |
| CVE-2026-100382 | UNKNOWN | — | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection. … | Sep 25, 2026 |
| CVE-2026-100381 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - UploadWizard Extension allows Cross-Site Scripting (XSS). This … | Sep 25, 2026 |
| CVE-2026-9313 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 25, 2026 |
| CVE-2026-96879 | UNKNOWN | — | Improper removal of sensitive information before storage or transfer vulnerability in Wikimedia Foundation's Mediawiki - FlaggedRevs extension through 1.46.0. | Sep 25, 2026 |
| CVE-2026-91769 | MEDIUM | 4.3 | PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires … | Sep 25, 2026 |
| CVE-2026-91767 | MEDIUM | 6.5 | php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer … | Sep 25, 2026 |
| CVE-2026-91766 | MEDIUM | 5.9 | When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a … | Sep 25, 2026 |
| CVE-2026-91765 | HIGH | 7.5 | cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing … | Sep 25, 2026 |
| CVE-2026-6103 | MEDIUM | 4.3 | phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and … | Sep 25, 2026 |
| CVE-2026-57864 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 25, 2026 |
| CVE-2026-57443 | HIGH | 7.5 | SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1, the AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) exposes the … | Sep 25, 2026 |
| CVE-2026-17545 | UNKNOWN | — | On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, … | Sep 25, 2026 |
| CVE-2026-10758 | HIGH | 7.5 | Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via … | Sep 25, 2026 |
| CVE-2026-100417 | LOW | 3.1 | RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from … | Sep 25, 2026 |
| CVE-2026-100391 | HIGH | 8.2 | MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query … | Sep 25, 2026 |
| CVE-2026-100390 | HIGH | 7.4 | Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can … | Sep 25, 2026 |
| CVE-2026-100389 | HIGH | 8.1 | GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated … | Sep 25, 2026 |