Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54449
Total
4308
Critical
16178
High
15893
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-42323 | HIGH | 7.2 | Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/batch_manager.php accepts administrator-controlled dimension width, height, and ratio values … | Sep 25, 2026 |
| CVE-2026-42322 | CRITICAL | 9.1 | Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_pages.php validates uploaded logo content by MIME type but … | Sep 25, 2026 |
| CVE-2026-39372 | MEDIUM | 4.9 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores and serves uploaded image attachments without stripping … | Sep 25, 2026 |
| CVE-2026-39353 | CRITICAL | 9.1 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a … | Sep 25, 2026 |
| CVE-2026-33639 | HIGH | 7.2 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane interpolates the administrator-controlled tax_rate_decimal_places setting into an ALTER … | Sep 25, 2026 |
| CVE-2026-100230 | MEDIUM | 5.3 | Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / versus \ distinction and allows … | Sep 25, 2026 |
| CVE-2026-97866 | MEDIUM | 5.6 | A weakness has been identified in Zhonglun CloudPOS 3.0. Affected by this vulnerability is an unknown functionality of the file Program.cs of the component Automatic … | Sep 25, 2026 |
| CVE-2026-96812 | UNKNOWN | — | Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE … | Sep 25, 2026 |
| CVE-2026-93306 | HIGH | 7.1 | IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web … | Sep 25, 2026 |
| CVE-2026-93030 | MEDIUM | 6.5 | FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw. | Sep 25, 2026 |
| CVE-2026-88389 | UNKNOWN | — | Espruino 2v29 (commit bffc6d0) contains a NULL pointer dereference vulnerability in jslGetRawString() in src/jslex.c. Crafted raw/binary string input can cause the lexer to pass a … | Sep 25, 2026 |
| CVE-2026-84882 | HIGH | 7.5 | IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this … | Sep 25, 2026 |
| CVE-2026-84862 | HIGH | 7.2 | IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute … | Sep 25, 2026 |
| CVE-2026-60101 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 25, 2026 |
| CVE-2026-60100 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 25, 2026 |
| CVE-2026-60099 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 25, 2026 |
| CVE-2026-60098 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 25, 2026 |
| CVE-2026-60097 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 25, 2026 |
| CVE-2026-60096 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 25, 2026 |
| CVE-2026-98162 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix tree connection leak in smb2_tree_connect() See the procedure below: smb2_tree_connect ksmbd_tree_conn_connect xa_store(&sess->tree_conns, tree_conn->id, … | Sep 25, 2026 |
| CVE-2026-98161 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: nvdimm: pmem: keep PREFLUSH before data writes pmem_submit_bio() records a REQ_PREFLUSH error, but continues to … | Sep 25, 2026 |
| CVE-2026-98160 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() padapter->HalData is allocated via vzalloc(), but … | Sep 25, 2026 |
| CVE-2026-97865 | HIGH | 7.3 | A security flaw has been discovered in Open-Web-Analytics up to 1.8.1. Affected is the function Event::loadFromArray of the file queue.php of the component Remote Event … | Sep 25, 2026 |
| CVE-2026-97864 | MEDIUM | 5.3 | A vulnerability has been found in GibbonEdu Gibbon up to 30.0.01. The affected element is the function makeBlock of the file modules/Planner/units_add_blockAjax.php of the component … | Sep 25, 2026 |
| CVE-2026-97222 | MEDIUM | 5.5 | A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed SheetObjectComponent element, the XML parser can … | Sep 25, 2026 |