Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54449
Total
4308
Critical
16178
High
15893
Medium
CVE ID Severity Score Description Published
CVE-2026-56724 UNKNOWN — Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An issue with permission checks in the knowledge base management area … Sep 25, 2026
CVE-2026-56723 UNKNOWN — Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a customer who can view a ticket cannot see internal ticket articles … Sep 25, 2026
CVE-2026-18320 MEDIUM 6.1 Readwise Reader for Android uses a sanitize-html configuration that permits all attributes on SVG and PATH elements due to a wildcard attribute rule. This configuration … Sep 25, 2026
CVE-2026-18312 MEDIUM 6.1 Readwise Reader for Android constructs URLs in its WebView using attacker-controlled metadata without proper encoding or escaping. The application interpolates untrusted values directly into URL … Sep 25, 2026
CVE-2026-18311 MEDIUM 6.1 Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata. Attacker-controlled fields such as … Sep 25, 2026
CVE-2026-100248 UNKNOWN — The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin. Sep 25, 2026
CVE-2026-100237 MEDIUM 6.1 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension allows Stored XSS. This issue affects … Sep 25, 2026
CVE-2026-97869 MEDIUM 4.1 A flaw has been found in langchain4j up to 1.5.3-beta10/1.11.10-beta18/1.18.1-beta27. This vulnerability affects the function AgenticScopeSerializer.fromJson of the file AgenticScopeJsonSerializationIT.java of the component LangChain4j-agentic. This … Sep 25, 2026
CVE-2026-97868 LOW 3.5 A security vulnerability has been detected in sheshbabu zen up to 1.5.0. Affected by this issue is the function dangerouslySetInnerHTML of the file features/notes/NotesEditor.jsx of … Sep 25, 2026
CVE-2026-97469 MEDIUM 4.3 PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline … Sep 25, 2026
CVE-2026-96874 UNKNOWN — Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in the Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - … Sep 25, 2026
CVE-2026-92161 CRITICAL 9.8 FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider … Sep 25, 2026
CVE-2026-85293 MEDIUM 4.8 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2-beta-1, InvoicePlane stores client_email values without enforcing email syntax and … Sep 25, 2026
CVE-2026-85292 MEDIUM 4.8 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's User_Controller compares the session user_type value with the … Sep 25, 2026
CVE-2026-85291 MEDIUM 6.5 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Users::change_password() method accepts a user_id from the URL … Sep 25, 2026
CVE-2026-85290 MEDIUM 5.3 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Cron::recur() method writes an invalid cron key from … Sep 25, 2026
CVE-2026-85289 MEDIUM 6.5 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane omits ensure_valid_post_request() from delete methods including Payments::delete(), Recurring::delete(), … Sep 25, 2026
CVE-2026-85274 MEDIUM 6.5 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Recurring::stop() as a state-changing GET route without … Sep 25, 2026
CVE-2026-67236 UNKNOWN — RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, a successful POST /login caused is_authorized/2 to set an auth cookie containing … Sep 25, 2026
CVE-2026-62262 CRITICAL 9.1 Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is enabled, an unauthenticated guest can … Sep 25, 2026
CVE-2026-54790 MEDIUM 6.0 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores an administrator-controlled custom_field_table value without validating it … Sep 25, 2026
CVE-2026-50547 HIGH 7.5 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Invoices::generate_xml() method appends a database-derived xml_id to the … Sep 25, 2026
CVE-2026-49850 HIGH 7.5 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Invoices::delete() and Invoices::delete_invoice_tax() as state-changing routes without … Sep 25, 2026
CVE-2026-44642 HIGH 8.1 Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, check_upgrade_access_rights() in admin/include/functions_upgrade.php conditionally escapes the submitted username only … Sep 25, 2026
CVE-2026-42324 HIGH 7.2 Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/element_set_ranks.php stores administrator-controlled image_order[] values without enforcing the existing … Sep 25, 2026