Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54227
Total
4299
Critical
16114
High
15798
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-59672 | UNKNOWN | — | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … | Oct 02, 2026 |
| CVE-2026-59665 | UNKNOWN | — | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … | Oct 02, 2026 |
| CVE-2026-59664 | UNKNOWN | — | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … | Oct 02, 2026 |
| CVE-2026-59663 | UNKNOWN | — | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … | Oct 02, 2026 |
| CVE-2026-59662 | UNKNOWN | — | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … | Oct 02, 2026 |
| CVE-2026-59661 | UNKNOWN | — | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … | Oct 02, 2026 |
| CVE-2026-59660 | UNKNOWN | — | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … | Oct 02, 2026 |
| CVE-2026-59659 | UNKNOWN | — | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … | Oct 02, 2026 |
| CVE-2026-104403 | MEDIUM | 5.3 | Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects LearnPress: from n/a through 4.4.9. | Oct 02, 2026 |
| CVE-2026-103885 | UNKNOWN | — | Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. A LDAP server using the LDAP API (like Apache DS) may consume 100% of a CPU … | Oct 02, 2026 |
| CVE-2026-103880 | UNKNOWN | — | Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP … | Oct 02, 2026 |
| CVE-2026-103878 | UNKNOWN | — | Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API. A StartTLS extended operation started after a Search request has been sent can lead … | Oct 02, 2026 |
| CVE-2026-103877 | UNKNOWN | — | Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with … | Oct 02, 2026 |
| CVE-2026-103552 | HIGH | 7.3 | Stack Overflow vulnerability in Apache Directory LDAP API. Before binding, a client can send a deeply nested search filter that overflows the stack in the … | Oct 02, 2026 |
| CVE-2026-102731 | UNKNOWN | — | Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A malicious peer (or a MITM) can send a small BER-encoded response causing … | Oct 02, 2026 |
| CVE-2026-95512 | MEDIUM | 5.5 | A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening … | Oct 02, 2026 |
| CVE-2026-91784 | UNKNOWN | — | cjbassi/gotop is vulnerable to local argument injection via process termination functionality. The process name is passed directly to pkill without sanitization. A local attacker can … | Oct 02, 2026 |
| CVE-2026-80464 | MEDIUM | 4.9 | Server-Side request forgery (SSRF) vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Server Side Request Forgery. This issue affects Sef - AI Chatbot … | Oct 02, 2026 |
| CVE-2026-80443 | HIGH | 7.4 | Improper certificate validation vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Adversary in the Middle (AiTM). This issue affects Sef - AI Chatbot … | Oct 02, 2026 |
| CVE-2026-80337 | MEDIUM | 5.3 | Missing Authorization vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sef - AI … | Oct 02, 2026 |
| CVE-2026-59671 | UNKNOWN | — | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … | Oct 02, 2026 |
| CVE-2026-59670 | UNKNOWN | — | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … | Oct 02, 2026 |
| CVE-2026-59669 | UNKNOWN | — | Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in … | Oct 02, 2026 |
| CVE-2026-97663 | HIGH | 7.2 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, … | Oct 02, 2026 |
| CVE-2026-97641 | HIGH | 7.2 | The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, … | Oct 02, 2026 |