Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54949
Total
4343
Critical
16375
High
16061
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-97149 | UNKNOWN | — | In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature only covers the method, expiry, … | Sep 24, 2026 |
| CVE-2026-96891 | CRITICAL | 9.8 | A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the … | Sep 24, 2026 |
| CVE-2026-96884 | MEDIUM | 6.3 | A security flaw has been discovered in MantisZip up to 0.4.5. Affected by this issue is the function Path.Combine of the file MainWindow.UI.cs of the … | Sep 24, 2026 |
| CVE-2026-96882 | MEDIUM | 5.3 | A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the function searchBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component … | Sep 24, 2026 |
| CVE-2026-96881 | MEDIUM | 5.3 | A vulnerability was determined in TaleLin lin-cms-spring-boot up to 0.2.1. Affected is the function getBooks of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. Executing … | Sep 24, 2026 |
| CVE-2026-97056 | MEDIUM | 6.8 | SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (which was not the default before v0.143.0), … | Sep 24, 2026 |
| CVE-2026-97055 | HIGH | 8.1 | SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() … | Sep 24, 2026 |
| CVE-2026-96880 | MEDIUM | 5.3 | A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1. This impacts the function getBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. Performing … | Sep 24, 2026 |
| CVE-2026-96810 | LOW | 3.5 | A vulnerability was identified in huanzi-qch base-admin up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1. This issue affects the function Save of the file base-admin-master\src\main\java\cn\huanzi\qch\baseadmin\common\controller\CommonController.java of the component Add User … | Sep 24, 2026 |
| CVE-2026-96803 | HIGH | 7.3 | A vulnerability was identified in java110 MicroCommunity up to 2.0. Affected is the function QueryServiceSMOImpl.fallBack of the file BusinessApi.java of the component fallBack API Endpoint. … | Sep 24, 2026 |
| CVE-2026-96777 | MEDIUM | 6.3 | A vulnerability was determined in Forma LMS up to 4.1.43. This impacts the function UserselectorAdmController::getDataTask of the file /appCore/ajax.adm_server.php?r=adm/userselector/getData of the component Multi-User-Selector AJAX Endpoint. … | Sep 24, 2026 |
| CVE-2026-18467 | CRITICAL | 9.8 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.3. The 5.0.3 … | Sep 24, 2026 |
| CVE-2026-96774 | MEDIUM | 5.3 | A vulnerability was found in SPON Communications IP Network Audio Device XC-9603 1.2.3_20181106 Build 107. This affects the function loadCfg of the file /ini/sys_cfg.txt of … | Sep 24, 2026 |
| CVE-2026-96773 | MEDIUM | 4.3 | A weakness has been identified in Intelliants Subrion CMS up to 4.2.1. This vulnerability affects the function iaUsers::authorize of the file front/login.php of the component … | Sep 24, 2026 |
| CVE-2026-96772 | MEDIUM | 5.3 | A security flaw has been discovered in Intelliants Subrion CMS up to 4.2.1. This affects an unknown part of the file /actions.json?action=assign-owner. The manipulation of … | Sep 24, 2026 |
| CVE-2026-96764 | MEDIUM | 4.3 | A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::GetReplicaListByRegex of the component Regular Expression Handler. Executing a manipulation … | Sep 24, 2026 |
| CVE-2026-96763 | MEDIUM | 5.4 | A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the function ScopedSegmentAccess::MountSegment of the file segment.cpp of the component … | Sep 24, 2026 |
| CVE-2026-96762 | HIGH | 7.3 | A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the … | Sep 24, 2026 |
| CVE-2026-96751 | HIGH | 7.3 | A vulnerability has been found in pmTicket Project-Management-Software up to 078fa56a782490c5059a0814f84df27984f4d7e2. This affects the function setSync of the file /ajax/add_project.php. Such manipulation of the argument … | Sep 24, 2026 |
| CVE-2026-96739 | MEDIUM | 4.3 | A flaw has been found in SEMCMS up to 4.2. Affected by this issue is some unknown functionality of the file /Edit/php/upload_json.php of the component … | Sep 24, 2026 |
| CVE-2026-93577 | CRITICAL | 9.9 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain … | Sep 24, 2026 |
| CVE-2026-92874 | MEDIUM | 5.4 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain … | Sep 24, 2026 |
| CVE-2026-92628 | LOW | 3.1 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under a … | Sep 24, 2026 |
| CVE-2026-92530 | MEDIUM | 4.3 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain … | Sep 24, 2026 |
| CVE-2026-92529 | MEDIUM | 4.3 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain … | Sep 24, 2026 |