Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54755
Total
4323
Critical
16270
High
16026
Medium
CVE ID Severity Score Description Published
CVE-2026-12559 UNKNOWN — A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue … Sep 24, 2026
CVE-2026-97360 CRITICAL 10.0 HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the … Sep 24, 2026
CVE-2026-97359 CRITICAL 10.0 HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by … Sep 24, 2026
CVE-2026-97062 MEDIUM 5.4 Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious … Sep 24, 2026
CVE-2026-97061 MEDIUM 4.3 Black Candy through 3.2.1 fails to scope playlist search queries to the authenticated session user, allowing any authenticated user to enumerate all playlists on the … Sep 24, 2026
CVE-2026-97059 HIGH 8.2 DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. … Sep 24, 2026
CVE-2026-97058 MEDIUM 5.3 sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can … Sep 24, 2026
CVE-2026-97057 HIGH 7.5 redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively … Sep 24, 2026
CVE-2026-95521 HIGH 7.8 A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct … Sep 24, 2026
CVE-2026-95519 HIGH 7.8 A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q … Sep 24, 2026
CVE-2026-91187 UNKNOWN — Improper Verification of Cryptographic Signature vulnerability in dashbit nimble_zta allows an unauthenticated remote attacker to authenticate as an arbitrary Cloudflare service token. Applications using the … Sep 24, 2026
CVE-2026-88360 UNKNOWN — libvips 8.19.0 contains a memory access vulnerability when processing little-endian PFM images. If the PFM text header length is not a multiple of four bytes, … Sep 24, 2026
CVE-2026-88359 UNKNOWN — libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted YAML document containing a very large literal or folded block scalar, … Sep 24, 2026
CVE-2026-77798 MEDIUM 6.5 Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock management bug in the user management module. Sep 24, 2026
CVE-2026-77797 LOW 3.6 Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files. Sep 24, 2026
CVE-2026-18857 LOW 3.4 IBM OPENBMC FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in the BMC firmware management interface. The host … Sep 24, 2026
CVE-2026-18104 LOW 3.3 IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES … Sep 24, 2026
CVE-2026-17511 LOW 3.4 IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition resource … Sep 24, 2026
CVE-2026-17504 MEDIUM 5.1 IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware … Sep 24, 2026
CVE-2026-17503 MEDIUM 5.1 IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware … Sep 24, 2026
CVE-2026-17413 MEDIUM 5.1 IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the RTAS firmware-to-OS … Sep 24, 2026
CVE-2026-97182 HIGH 7.3 A security vulnerability has been detected in halo-dev Halo up to 2.25.4/2.26.1. Affected is an unknown function of the file application/src/main/java/run/halo/app/content/comment/ReplyNotificationSubscriptionHelper.java of the component SpEL … Sep 24, 2026
CVE-2026-96515 UNKNOWN — This vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input validation controls in the diagnostic script import functionality. An authenticated … Sep 24, 2026
CVE-2026-94416 MEDIUM 6.8 An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key … Sep 24, 2026
CVE-2026-88916 MEDIUM 6.8 Incorrect Authorization vulnerability in TÜBİTAK ULAKBİM UlakPDF allows Privilege Escalation. This issue affects UlakPDF: through 09092026. Sep 24, 2026