Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54449
Total
4308
Critical
16178
High
15893
Medium
CVE ID Severity Score Description Published
CVE-2026-42323 HIGH 7.2 Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/batch_manager.php accepts administrator-controlled dimension width, height, and ratio values … Sep 25, 2026
CVE-2026-42322 CRITICAL 9.1 Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_pages.php validates uploaded logo content by MIME type but … Sep 25, 2026
CVE-2026-39372 MEDIUM 4.9 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores and serves uploaded image attachments without stripping … Sep 25, 2026
CVE-2026-39353 CRITICAL 9.1 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a … Sep 25, 2026
CVE-2026-33639 HIGH 7.2 InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane interpolates the administrator-controlled tax_rate_decimal_places setting into an ALTER … Sep 25, 2026
CVE-2026-100230 MEDIUM 5.3 Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / versus \ distinction and allows … Sep 25, 2026
CVE-2026-97866 MEDIUM 5.6 A weakness has been identified in Zhonglun CloudPOS 3.0. Affected by this vulnerability is an unknown functionality of the file Program.cs of the component Automatic … Sep 25, 2026
CVE-2026-96812 UNKNOWN — Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE … Sep 25, 2026
CVE-2026-93306 HIGH 7.1 IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web … Sep 25, 2026
CVE-2026-93030 MEDIUM 6.5 FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw. Sep 25, 2026
CVE-2026-88389 UNKNOWN — Espruino 2v29 (commit bffc6d0) contains a NULL pointer dereference vulnerability in jslGetRawString() in src/jslex.c. Crafted raw/binary string input can cause the lexer to pass a … Sep 25, 2026
CVE-2026-84882 HIGH 7.5 IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this … Sep 25, 2026
CVE-2026-84862 HIGH 7.2 IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute … Sep 25, 2026
CVE-2026-60101 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Sep 25, 2026
CVE-2026-60100 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Sep 25, 2026
CVE-2026-60099 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Sep 25, 2026
CVE-2026-60098 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Sep 25, 2026
CVE-2026-60097 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Sep 25, 2026
CVE-2026-60096 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Sep 25, 2026
CVE-2026-98162 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: smb/server: fix tree connection leak in smb2_tree_connect() See the procedure below: smb2_tree_connect ksmbd_tree_conn_connect xa_store(&sess->tree_conns, tree_conn->id, … Sep 25, 2026
CVE-2026-98161 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: nvdimm: pmem: keep PREFLUSH before data writes pmem_submit_bio() records a REQ_PREFLUSH error, but continues to … Sep 25, 2026
CVE-2026-98160 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() padapter->HalData is allocated via vzalloc(), but … Sep 25, 2026
CVE-2026-97865 HIGH 7.3 A security flaw has been discovered in Open-Web-Analytics up to 1.8.1. Affected is the function Event::loadFromArray of the file queue.php of the component Remote Event … Sep 25, 2026
CVE-2026-97864 MEDIUM 5.3 A vulnerability has been found in GibbonEdu Gibbon up to 30.0.01. The affected element is the function makeBlock of the file modules/Planner/units_add_blockAjax.php of the component … Sep 25, 2026
CVE-2026-97222 MEDIUM 5.5 A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed SheetObjectComponent element, the XML parser can … Sep 25, 2026