Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54499
Total
4309
Critical
16193
High
15930
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-97650 | MEDIUM | 4.3 | A vulnerability has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function echo of the file admin/fun/addLog.php. The manipulation … | Sep 25, 2026 |
| CVE-2026-97723 | MEDIUM | 5.4 | madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (XSS) vulnerability in the chat message rendering functionality. User-controlled URLs in chat messages were insufficiently neutralized … | Sep 25, 2026 |
| CVE-2026-97649 | MEDIUM | 4.7 | A flaw has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this vulnerability is an unknown functionality of the file example_lite.sql. Executing a … | Sep 25, 2026 |
| CVE-2026-97648 | MEDIUM | 4.3 | A vulnerability was detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function. Performing a manipulation results in cross-site request forgery. It is … | Sep 25, 2026 |
| CVE-2026-97647 | MEDIUM | 5.3 | A security vulnerability has been detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This impacts an unknown function of the file user/editLog.php. Such manipulation of the … | Sep 25, 2026 |
| CVE-2026-95811 | MEDIUM | 6.5 | Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass … | Sep 25, 2026 |
| CVE-2026-97646 | HIGH | 7.3 | A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This affects an unknown function of the file admin/fun/getStudent.php. This manipulation of the argument … | Sep 25, 2026 |
| CVE-2026-92289 | UNKNOWN | — | Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not … | Sep 25, 2026 |
| CVE-2026-92288 | CRITICAL | 9.1 | Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret … | Sep 25, 2026 |
| CVE-2026-85417 | UNKNOWN | — | Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions. Individuals … | Sep 25, 2026 |
| CVE-2026-53493 | UNKNOWN | — | containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory … | Sep 25, 2026 |
| CVE-2026-85082 | UNKNOWN | — | Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely separating the filename from the command. | Sep 25, 2026 |
| CVE-2026-84283 | UNKNOWN | — | Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-storage tree. A local application or file manager that … | Sep 25, 2026 |
| CVE-2026-97387 | UNKNOWN | — | Rejected reason: This CVE is a duplicate of another CVE. | Sep 24, 2026 |
| CVE-2026-97230 | CRITICAL | 9.8 | IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate … | Sep 24, 2026 |
| CVE-2026-97636 | UNKNOWN | — | Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author … | Sep 24, 2026 |
| CVE-2026-87722 | UNKNOWN | — | Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search query predicates (such as RegexProjectPredicate, RegexRefPredicate, RegexPathPredicate, and sibling predicates) and REST regex filter endpoints (RegexListSearcher … | Sep 24, 2026 |
| CVE-2026-87721 | UNKNOWN | — | Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in Gerrit Code Review versions 2.0.19 through 3.12.9, 3.13.0 … | Sep 24, 2026 |
| CVE-2026-87720 | UNKNOWN | — | Incorrect Authorization (CWE-863) in project name normalization (ProjectUtil.stripGitSuffix) and ProjectCache eviction logic (ProjectCacheImpl) in Gerrit Code Review versions 2.16.0 through 3.12.9, 3.13.0 through 3.13.8, and … | Sep 24, 2026 |
| CVE-2026-85491 | UNKNOWN | — | Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch … | Sep 24, 2026 |
| CVE-2026-97368 | MEDIUM | 6.3 | A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInfo of the file blade-service/blade-system/src/main/java/org/springblade/system/service/impl/UserServiceImpl.java of the component user-auth-info Endpoint. … | Sep 24, 2026 |
| CVE-2026-97366 | MEDIUM | 6.3 | A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function openDevTools of the file electron/window.js of the … | Sep 24, 2026 |
| CVE-2026-95699 | CRITICAL | 9.6 | Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data … | Sep 24, 2026 |
| CVE-2026-93353 | MEDIUM | 5.3 | copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users to create, remove, and truncate arbitrary paths outside … | Sep 24, 2026 |
| CVE-2026-88388 | HIGH | 7.5 | Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace handling path on 64-bit builds. A remote attacker can supply … | Sep 24, 2026 |