Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54227
Total
4299
Critical
16114
High
15798
Medium
CVE ID Severity Score Description Published
CVE-2026-104424 LOW 3.7 Zebra before 6.1.0 contains an incorrect calculation vulnerability in its ZIP-317 block template selector that omits header and transaction-count size from the block budget. Attackers … Oct 02, 2026
CVE-2026-104423 HIGH 7.5 Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid … Oct 02, 2026
CVE-2026-104422 HIGH 7.5 The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that appear too … Oct 02, 2026
CVE-2026-104421 MEDIUM 5.3 Zebra before 6.2.1 contains an incomplete cleanup vulnerability that allows unauthenticated peers to block downloading of valid blocks by leaving rejected hashes in SentHashes. Attackers … Oct 02, 2026
CVE-2026-104420 MEDIUM 5.3 Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossiped blocks. The inbound cleanup step … Oct 02, 2026
CVE-2026-104419 MEDIUM 4.8 Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever … Oct 02, 2026
CVE-2026-104418 HIGH 7.2 Ghost from 6.10.3 before 6.64.0 contains a remote code execution vulnerability that allows authenticated administrators to run code by abusing theme translation file loading. Attackers … Oct 02, 2026
CVE-2026-104417 MEDIUM 4.9 Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in theme translation file loading that allows authenticated administrators to read JSON files outside the … Oct 02, 2026
CVE-2026-104416 HIGH 7.5 Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff … Oct 02, 2026
CVE-2026-104415 LOW 3.1 Ghost from 0.7.2 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff-level users to determine the relative ordering of other … Oct 02, 2026
CVE-2026-104414 HIGH 8.1 Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post content via oEmbed photo responses. … Oct 02, 2026
CVE-2026-104413 HIGH 7.3 Ghost from 5.94.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users, including Contributors, to host arbitrary HTML by abusing bookmark card … Oct 02, 2026
CVE-2026-104412 MEDIUM 4.3 Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign their own role … Oct 02, 2026
CVE-2026-104411 HIGH 7.3 Ghost from 6.22.1 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users to host scripts by uploading files served with extension-derived content … Oct 02, 2026
CVE-2026-104410 HIGH 7.5 SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled database rows via the /api/export/preview endpoint. Attackers can … Oct 02, 2026
CVE-2026-103763 MEDIUM 5.8 SiYuan before v3.8.5 contains an information disclosure vulnerability that allows read-only publish readers to learn metadata of publish-excluded documents through the getNotebookInfo endpoint. Attackers, including … Oct 02, 2026
CVE-2026-103762 MEDIUM 5.3 SiYuan before v3.8.5 contains a missing authorization vulnerability in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints that allows read-only publish visitors to learn unpublished notebook box … Oct 02, 2026
CVE-2026-97876 MEDIUM 6.4 A local attacker with control over GRUB's configuration can bypass lockdown restrictions when booting with Secure Boot and load an unsigned GRUB module, while GRUB … Oct 02, 2026
CVE-2026-96990 UNKNOWN — Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade … Oct 02, 2026
CVE-2026-94651 UNKNOWN — improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings. This issue affects Apache Thrift: before 0.25.0. … Oct 02, 2026
CVE-2026-94650 UNKNOWN — Uncontrolled Recursion vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes … Oct 02, 2026
CVE-2026-94645 UNKNOWN — Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: … Oct 02, 2026
CVE-2026-94644 UNKNOWN — Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade … Oct 02, 2026
CVE-2026-94642 UNKNOWN — Uncaught exception vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes … Oct 02, 2026
CVE-2026-94633 UNKNOWN — Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Dart bindings. This issue affects Apache Thrift: before 0.25.0. … Oct 02, 2026