Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54227
Total
4299
Critical
16114
High
15798
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-104424 | LOW | 3.7 | Zebra before 6.1.0 contains an incorrect calculation vulnerability in its ZIP-317 block template selector that omits header and transaction-count size from the block budget. Attackers … | Oct 02, 2026 |
| CVE-2026-104423 | HIGH | 7.5 | Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid … | Oct 02, 2026 |
| CVE-2026-104422 | HIGH | 7.5 | The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that appear too … | Oct 02, 2026 |
| CVE-2026-104421 | MEDIUM | 5.3 | Zebra before 6.2.1 contains an incomplete cleanup vulnerability that allows unauthenticated peers to block downloading of valid blocks by leaving rejected hashes in SentHashes. Attackers … | Oct 02, 2026 |
| CVE-2026-104420 | MEDIUM | 5.3 | Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossiped blocks. The inbound cleanup step … | Oct 02, 2026 |
| CVE-2026-104419 | MEDIUM | 4.8 | Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever … | Oct 02, 2026 |
| CVE-2026-104418 | HIGH | 7.2 | Ghost from 6.10.3 before 6.64.0 contains a remote code execution vulnerability that allows authenticated administrators to run code by abusing theme translation file loading. Attackers … | Oct 02, 2026 |
| CVE-2026-104417 | MEDIUM | 4.9 | Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in theme translation file loading that allows authenticated administrators to read JSON files outside the … | Oct 02, 2026 |
| CVE-2026-104416 | HIGH | 7.5 | Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff … | Oct 02, 2026 |
| CVE-2026-104415 | LOW | 3.1 | Ghost from 0.7.2 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff-level users to determine the relative ordering of other … | Oct 02, 2026 |
| CVE-2026-104414 | HIGH | 8.1 | Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post content via oEmbed photo responses. … | Oct 02, 2026 |
| CVE-2026-104413 | HIGH | 7.3 | Ghost from 5.94.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users, including Contributors, to host arbitrary HTML by abusing bookmark card … | Oct 02, 2026 |
| CVE-2026-104412 | MEDIUM | 4.3 | Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign their own role … | Oct 02, 2026 |
| CVE-2026-104411 | HIGH | 7.3 | Ghost from 6.22.1 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users to host scripts by uploading files served with extension-derived content … | Oct 02, 2026 |
| CVE-2026-104410 | HIGH | 7.5 | SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled database rows via the /api/export/preview endpoint. Attackers can … | Oct 02, 2026 |
| CVE-2026-103763 | MEDIUM | 5.8 | SiYuan before v3.8.5 contains an information disclosure vulnerability that allows read-only publish readers to learn metadata of publish-excluded documents through the getNotebookInfo endpoint. Attackers, including … | Oct 02, 2026 |
| CVE-2026-103762 | MEDIUM | 5.3 | SiYuan before v3.8.5 contains a missing authorization vulnerability in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints that allows read-only publish visitors to learn unpublished notebook box … | Oct 02, 2026 |
| CVE-2026-97876 | MEDIUM | 6.4 | A local attacker with control over GRUB's configuration can bypass lockdown restrictions when booting with Secure Boot and load an unsigned GRUB module, while GRUB … | Oct 02, 2026 |
| CVE-2026-96990 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Erlang bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade … | Oct 02, 2026 |
| CVE-2026-94651 | UNKNOWN | — | improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings. This issue affects Apache Thrift: before 0.25.0. … | Oct 02, 2026 |
| CVE-2026-94650 | UNKNOWN | — | Uncontrolled Recursion vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes … | Oct 02, 2026 |
| CVE-2026-94645 | UNKNOWN | — | Improper validation of specified quantity in input, Allocation of resources without limits or throttling vulnerability in Apache Thrift nodejs bindings. This issue affects Apache Thrift: … | Oct 02, 2026 |
| CVE-2026-94644 | UNKNOWN | — | Allocation of resources without limits or throttling vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade … | Oct 02, 2026 |
| CVE-2026-94642 | UNKNOWN | — | Uncaught exception vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes … | Oct 02, 2026 |
| CVE-2026-94633 | UNKNOWN | — | Memory allocation with excessive size value, Improper handling of length parameter inconsistency vulnerability in Apache Thrift Dart bindings. This issue affects Apache Thrift: before 0.25.0. … | Oct 02, 2026 |