Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54449
Total
4308
Critical
16178
High
15893
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-100388 | MEDIUM | 5.4 | RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS. … | Sep 25, 2026 |
| CVE-2026-100387 | HIGH | 8.1 | pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers … | Sep 25, 2026 |
| CVE-2026-100380 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Site Scripting (XSS). This … | Sep 25, 2026 |
| CVE-2026-100379 | UNKNOWN | — | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP Cookies. This issue affects Wikipedia Android App: … | Sep 25, 2026 |
| CVE-2026-100378 | UNKNOWN | — | Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - Translate Extension: … | Sep 25, 2026 |
| CVE-2026-100377 | UNKNOWN | — | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Excavation. This issue affects Mediawiki - WikiLambda Extension: … | Sep 25, 2026 |
| CVE-2026-100376 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Cross-Site Scripting (XSS). This … | Sep 25, 2026 |
| CVE-2026-100369 | HIGH | 8.4 | CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs and wrapping executable processes. `CliInvoke` versions 2.0.0 through 2.8.4, 2.9.0 through … | Sep 25, 2026 |
| CVE-2025-1218 | LOW | 3.4 | The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or … | Sep 25, 2026 |
| CVE-2025-14181 | MEDIUM | 6.5 | The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not … | Sep 25, 2026 |
| CVE-2026-96878 | UNKNOWN | — | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo … | Sep 25, 2026 |
| CVE-2026-96877 | UNKNOWN | — | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo … | Sep 25, 2026 |
| CVE-2026-96876 | UNKNOWN | — | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo … | Sep 25, 2026 |
| CVE-2026-96875 | UNKNOWN | — | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - Cargo … | Sep 25, 2026 |
| CVE-2026-93682 | MEDIUM | 5.8 | When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte … | Sep 25, 2026 |
| CVE-2026-5267 | HIGH | 7.5 | Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with … | Sep 25, 2026 |
| CVE-2026-57861 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 25, 2026 |
| CVE-2026-53990 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 25, 2026 |
| CVE-2026-100373 | MEDIUM | 4.1 | OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses. Users … | Sep 25, 2026 |
| CVE-2026-100372 | HIGH | 7.2 | ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory … | Sep 25, 2026 |
| CVE-2026-100368 | HIGH | 8.4 | CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide specialized wrappers for shells such as PowerShell and Windows Command Prompt. … | Sep 25, 2026 |
| CVE-2026-100310 | HIGH | 7.0 | GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can … | Sep 25, 2026 |
| CVE-2026-100208 | HIGH | 7.5 | Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | Sep 25, 2026 |
| CVE-2026-97897 | LOW | 3.5 | A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component … | Sep 25, 2026 |
| CVE-2026-97896 | LOW | 3.5 | A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationForm::rules of the file packages/Webkul/Admin/src/Http/Requests/ConfigurationForm.php of the component Upload Functionality. … | Sep 25, 2026 |