Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54449
Total
4308
Critical
16178
High
15893
Medium
CVE ID Severity Score Description Published
CVE-2026-100388 MEDIUM 5.4 RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS. … Sep 25, 2026
CVE-2026-100387 HIGH 8.1 pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers … Sep 25, 2026
CVE-2026-100380 UNKNOWN — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Site Scripting (XSS). This … Sep 25, 2026
CVE-2026-100379 UNKNOWN — Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP Cookies. This issue affects Wikipedia Android App: … Sep 25, 2026
CVE-2026-100378 UNKNOWN — Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - Translate Extension: … Sep 25, 2026
CVE-2026-100377 UNKNOWN — Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Excavation. This issue affects Mediawiki - WikiLambda Extension: … Sep 25, 2026
CVE-2026-100376 UNKNOWN — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Cross-Site Scripting (XSS). This … Sep 25, 2026
CVE-2026-100369 HIGH 8.4 CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs and wrapping executable processes. `CliInvoke` versions 2.0.0 through 2.8.4, 2.9.0 through … Sep 25, 2026
CVE-2025-1218 LOW 3.4 The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or … Sep 25, 2026
CVE-2025-14181 MEDIUM 6.5 The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not … Sep 25, 2026
CVE-2026-96878 UNKNOWN — Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo … Sep 25, 2026
CVE-2026-96877 UNKNOWN — Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo … Sep 25, 2026
CVE-2026-96876 UNKNOWN — Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo … Sep 25, 2026
CVE-2026-96875 UNKNOWN — Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - Cargo … Sep 25, 2026
CVE-2026-93682 MEDIUM 5.8 When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte … Sep 25, 2026
CVE-2026-5267 HIGH 7.5 Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with … Sep 25, 2026
CVE-2026-57861 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Sep 25, 2026
CVE-2026-53990 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Sep 25, 2026
CVE-2026-100373 MEDIUM 4.1 OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses. Users … Sep 25, 2026
CVE-2026-100372 HIGH 7.2 ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory … Sep 25, 2026
CVE-2026-100368 HIGH 8.4 CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide specialized wrappers for shells such as PowerShell and Windows Command Prompt. … Sep 25, 2026
CVE-2026-100310 HIGH 7.0 GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can … Sep 25, 2026
CVE-2026-100208 HIGH 7.5 Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. Sep 25, 2026
CVE-2026-97897 LOW 3.5 A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component … Sep 25, 2026
CVE-2026-97896 LOW 3.5 A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationForm::rules of the file packages/Webkul/Admin/src/Http/Requests/ConfigurationForm.php of the component Upload Functionality. … Sep 25, 2026