Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54949
Total
4343
Critical
16375
High
16061
Medium
CVE ID Severity Score Description Published
CVE-2026-73064 LOW 2.9 In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes … Sep 24, 2026
CVE-2026-6544 MEDIUM 6.2 IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and … Sep 24, 2026
CVE-2026-65422 MEDIUM 6.5 A flaw in the authorization mechanism for Media Gateway API in Genetec Security Center may allow a user with no playback privileges to generate video … Sep 24, 2026
CVE-2026-58008 HIGH 8.1 Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through … Sep 24, 2026
CVE-2026-58007 HIGH 8.1 Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through … Sep 24, 2026
CVE-2026-58006 HIGH 8.1 Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through … Sep 24, 2026
CVE-2026-58005 HIGH 8.1 Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0. Sep 24, 2026
CVE-2026-58004 HIGH 8.1 Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0. Sep 24, 2026
CVE-2026-56736 HIGH 8.2 phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in versions prior to 4.2.0-alpha allows any unauthenticated user (or low-privileged … Sep 24, 2026
CVE-2026-52001 UNKNOWN — An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker to obtain sensitive information via the SSE transport eventSourceInit fetch wrapper " src/lib/utils.ts Sep 24, 2026
CVE-2026-51997 UNKNOWN — An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functions Sep 24, 2026
CVE-2026-51996 UNKNOWN — An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function Sep 24, 2026
CVE-2026-51995 HIGH 7.5 An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information via the src/lib/authorization-server-metadata.ts, src/lib/utils.ts components Sep 24, 2026
CVE-2026-51994 UNKNOWN — mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authenticate header Sep 24, 2026
CVE-2026-19492 LOW 3.2 IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interface. An attacker … Sep 24, 2026
CVE-2026-18870 MEDIUM 4.3 IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 could allow a remote attacker to obtain sensitive information … Sep 24, 2026
CVE-2026-13467 HIGH 8.1 Out-of-bounds write vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0. Sep 24, 2026
CVE-2026-13466 HIGH 8.1 Incorrect calculation of buffer size vulnerability in Altera Trusted Firmware on HPS allows Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0. Sep 24, 2026
CVE-2026-13465 HIGH 8.1 Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through … Sep 24, 2026
CVE-2026-12559 UNKNOWN — A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue … Sep 24, 2026
CVE-2026-97360 CRITICAL 10.0 HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the … Sep 24, 2026
CVE-2026-97359 CRITICAL 10.0 HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by … Sep 24, 2026
CVE-2026-97062 MEDIUM 5.4 Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious … Sep 24, 2026
CVE-2026-97061 MEDIUM 4.3 Black Candy through 3.2.1 fails to scope playlist search queries to the authenticated session user, allowing any authenticated user to enumerate all playlists on the … Sep 24, 2026
CVE-2026-97059 HIGH 8.2 DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. … Sep 24, 2026