Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54704
Total
4321
Critical
16261
High
15994
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-91122 | HIGH | 8.7 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the video placeholder component allowed crafted HTML to cause an attribute breakout … | Sep 24, 2026 |
| CVE-2026-88390 | HIGH | 7.7 | An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted JavaScript input containing an overlong token to trigger a one-byte write beyond … | Sep 24, 2026 |
| CVE-2026-88385 | UNKNOWN | — | Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data() during malformed XML parsing. Specially crafted XML input can cause text nodes allocated by mxmlNewText() to … | Sep 24, 2026 |
| CVE-2026-88384 | MEDIUM | 5.5 | OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path. A specially crafted EXR file containing an unknown-type attribute with dataSize set … | Sep 24, 2026 |
| CVE-2026-88383 | UNKNOWN | — | libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind(). When parsing iCalendar data containing a parameterized property, the function passes icalparameter_compare_kind_map() to bsearch() through an … | Sep 24, 2026 |
| CVE-2026-88382 | HIGH | 7.5 | hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggregate parser. | Sep 24, 2026 |
| CVE-2026-88378 | UNKNOWN | — | QuickJS commit 04be24600 contains a heap out-of-bounds write condition in JS_ReadFunctionTag(). | Sep 24, 2026 |
| CVE-2026-88377 | UNKNOWN | — | Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers. A specially crafted MP4 file containing an atom with a … | Sep 24, 2026 |
| CVE-2026-88376 | HIGH | 7.5 | Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create(). A specially crafted MP4 file containing an avcC or hvcC atom with a declared … | Sep 24, 2026 |
| CVE-2026-88373 | UNKNOWN | — | libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL() is called with a zero-length NAL unit, the resulting … | Sep 24, 2026 |
| CVE-2026-88372 | HIGH | 7.5 | libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) files. | Sep 24, 2026 |
| CVE-2026-88367 | UNKNOWN | — | NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasterization. A specially crafted SVG document containing an extremely large stroke-width can … | Sep 24, 2026 |
| CVE-2026-84302 | MEDIUM | 4.2 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Discourse AI reviewables associated with private messages could appear in the moderator … | Sep 24, 2026 |
| CVE-2026-79766 | CRITICAL | 9.1 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.1 until 2.5.1, an authenticated Termix administrator can store … | Sep 24, 2026 |
| CVE-2026-79764 | HIGH | 7.7 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0 until 2.5.1, the /homepage/proxy endpoint accepts an authenticated … | Sep 24, 2026 |
| CVE-2026-79763 | MEDIUM | 5.3 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.0 until 2.5.1, the POST /users/totp/disable and POST /users/totp/backup-codes … | Sep 24, 2026 |
| CVE-2026-79762 | MEDIUM | 5.5 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0 until 2.5.1, Termix derives the keys that wrap … | Sep 24, 2026 |
| CVE-2026-63498 | HIGH | 8.7 | Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload … | Sep 24, 2026 |
| CVE-2026-63493 | UNKNOWN | — | Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with self.api permission can reach the personal-access-token API flow … | Sep 24, 2026 |
| CVE-2026-62368 | HIGH | 8.1 | Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that … | Sep 24, 2026 |
| CVE-2026-56744 | UNKNOWN | — | `@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@bsv/wallet-toolbox-mobile` provide client-focused distributions for standard and mobile applications using wallet storage services. A … | Sep 24, 2026 |
| CVE-2026-56738 | UNKNOWN | — | phpMyFAQ is an open source FAQ web application. The `StopWords::add()` method inversions prior to 4.1.6 builds a SQL `INSERT` statement using `sprintf()` and inserts the … | Sep 24, 2026 |
| CVE-2026-47132 | MEDIUM | 5.4 | phpMyFAQ is an open source FAQ web application. Prior to version 4.2.0-alpha, an authenticated SQL LIKE wildcard injection vulnerability in phpMyFAQ’s chat user search allows … | Sep 24, 2026 |
| CVE-2026-26054 | UNKNOWN | — | SumatraPDF is a multi-format reader for Windows. Prior to 3.6, the MobiDoc::ParseHeader function in src/MobiDoc.cpp validates a record using kMobiHeaderMinLen but DecodeMobiDocHeader constructs a decoder … | Sep 24, 2026 |
| CVE-2026-97226 | MEDIUM | 6.3 | A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the file packages/api/src/controllers/files.js of the component files-style Endpoint. The … | Sep 24, 2026 |