Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54949
Total
4343
Critical
16375
High
16061
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-75907 | HIGH | 7.5 | The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID stored on an NTAG212 NFC … | Sep 24, 2026 |
| CVE-2026-67233 | UNKNOWN | — | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The shovel management resource's is_authorized/2 delegates to rabbit_mgmt_util:is_authorized_monitor/2, which … | Sep 24, 2026 |
| CVE-2026-63630 | LOW | 3.4 | BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, deserializeWorkflow() accepts the Timestamp node's tsaUrl control from imported JSON without … | Sep 24, 2026 |
| CVE-2026-63203 | HIGH | 7.6 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API handlers in packages/core/src/routes/account/third-party-tokens.ts allow a caller … | Sep 24, 2026 |
| CVE-2026-56739 | UNKNOWN | — | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.43.0, Logto fetches administrator-controlled outbound destinations without validating the address used … | Sep 24, 2026 |
| CVE-2026-56737 | HIGH | 8.1 | phpMyFAQ is an open source FAQ web application. Versions 3.2.0 through 4.1.5 contain an authentication bypass in its public two-factor authentication verification flow: an unauthenticated … | Sep 24, 2026 |
| CVE-2025-32000 | MEDIUM | 4.3 | HCL Sametime is vulnerable to insufficient input sanitization. The application did not appropriately sanitize user input. When user input is implicitly or explicitly trusted without … | Sep 24, 2026 |
| CVE-2026-97404 | UNKNOWN | — | In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticated remote attacker who … | Sep 24, 2026 |
| CVE-2026-97362 | HIGH | 7.5 | HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by … | Sep 24, 2026 |
| CVE-2026-97224 | MEDIUM | 4.3 | A vulnerability was detected in Excalidraw up to 0.18.1. The impacted element is an unknown function of the file packages/excalidraw/data/restore.ts of the component Imported File … | Sep 24, 2026 |
| CVE-2026-90959 | HIGH | 8.1 | A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify … | Sep 24, 2026 |
| CVE-2026-90481 | UNKNOWN | — | In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel. | Sep 24, 2026 |
| CVE-2026-88351 | UNKNOWN | — | An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specially crafted MessagePack array32 or map32 … | Sep 24, 2026 |
| CVE-2026-82094 | HIGH | 7.1 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of … | Sep 24, 2026 |
| CVE-2026-82093 | HIGH | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data. | Sep 24, 2026 |
| CVE-2026-81552 | HIGH | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of environment variables. | Sep 24, 2026 |
| CVE-2026-81549 | CRITICAL | 9.6 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto … | Sep 24, 2026 |
| CVE-2026-81548 | HIGH | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements … | Sep 24, 2026 |
| CVE-2026-81547 | HIGH | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to path traversal. | Sep 24, 2026 |
| CVE-2026-81545 | HIGH | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements … | Sep 24, 2026 |
| CVE-2026-81539 | HIGH | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements … | Sep 24, 2026 |
| CVE-2026-77874 | HIGH | 8.6 | IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted … | Sep 24, 2026 |
| CVE-2026-77825 | MEDIUM | 4.9 | IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses … | Sep 24, 2026 |
| CVE-2026-77707 | MEDIUM | 5.9 | Improper certificate validation vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from 1.0 before … | Sep 24, 2026 |
| CVE-2026-77703 | MEDIUM | 5.9 | Key exchange without entity authentication vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from … | Sep 24, 2026 |