Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54949
Total
4343
Critical
16375
High
16061
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-92470 | HIGH | 7.7 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain … | Sep 24, 2026 |
| CVE-2026-89078 | CRITICAL | 9.9 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain … | Sep 24, 2026 |
| CVE-2026-82370 | UNKNOWN | — | Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service permits network-adjacent attackers to execute arbitrary administrative switch CLI commands and issue container management … | Sep 24, 2026 |
| CVE-2026-96680 | MEDIUM | 4.3 | A vulnerability was detected in ByteDance Coze Scraper Extension up to 2.0.2. Affected by this vulnerability is the function chrome.runtime.onMessageExternal.addListener of the file static/background/index.js of … | Sep 23, 2026 |
| CVE-2026-96678 | MEDIUM | 6.3 | A security vulnerability has been detected in weiqingwen spring-boot-forum up to 538eecc3c6b85fdf0768ab4e8354b48c0c17d94f. Affected is the function validate of the file src/main/java/com/qingwenwei/util/NewUserFormValidator.java of the component Avatar … | Sep 23, 2026 |
| CVE-2026-96676 | MEDIUM | 6.3 | A vulnerability was identified in Fast FAC1900R 20190827_2.0.2. The impacted element is the function get_alias_name of the component uhttpd. Such manipulation leads to stack-based buffer … | Sep 23, 2026 |
| CVE-2026-96606 | MEDIUM | 5.3 | A security flaw has been discovered in LB-Link BL-CPE600EU 5.8.13. This vulnerability affects unknown code of the file Mifi_config.bin of the component Configuration Backup Handler. … | Sep 23, 2026 |
| CVE-2026-70125 | HIGH | 8.8 | Microsoft Outlook Remote Code Execution Vulnerability | Sep 23, 2026 |
| CVE-2026-59980 | UNKNOWN | — | hpack is an HTTP/2 Header Encoding for Python. Prior to version 4.2.0, unbounded variable integer decoding can cause run-away computation on malformed input leading to … | Sep 23, 2026 |
| CVE-2026-57168 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-56120. Reason: This candidate is a duplicate of CVE-2026-56120. Notes: All CVE users … | Sep 23, 2026 |
| CVE-2026-96604 | HIGH | 7.3 | A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. This affects the function strip_data of the file engine/modules/search.php of the component Search Module. … | Sep 23, 2026 |
| CVE-2026-96603 | HIGH | 7.3 | A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the function confirm_logged_in/confirm_user of the file functions.php of the component Admin Handler. Such manipulation of … | Sep 23, 2026 |
| CVE-2026-96602 | HIGH | 7.3 | A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin.php of the component Customer Login Handler. This manipulation … | Sep 23, 2026 |
| CVE-2026-96601 | HIGH | 7.3 | A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an unknown function of the file index.php of the component Admin Login Handler. The manipulation of … | Sep 23, 2026 |
| CVE-2026-93352 | CRITICAL | 9.8 | Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist … | Sep 23, 2026 |
| CVE-2026-86583 | HIGH | 8.8 | The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the … | Sep 23, 2026 |
| CVE-2026-81537 | HIGH | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection. | Sep 23, 2026 |
| CVE-2026-81536 | HIGH | 7.7 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) … | Sep 23, 2026 |
| CVE-2026-81208 | HIGH | 7.7 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An … | Sep 23, 2026 |
| CVE-2026-80423 | HIGH | 8.8 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets … | Sep 23, 2026 |
| CVE-2026-75887 | HIGH | 7.5 | A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters … | Sep 23, 2026 |
| CVE-2026-57854 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 23, 2026 |
| CVE-2026-19125 | HIGH | 8.1 | The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to … | Sep 23, 2026 |
| CVE-2026-96556 | HIGH | 7.3 | A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function addcashier of the file AddCashierCode.php. Executing a manipulation of the … | Sep 23, 2026 |
| CVE-2026-82369 | UNKNOWN | — | Insufficient input sanitization of shell metacharacters in the Brocade SANnav CLI scripting component permits authenticated users to break out of restricted execution contexts on managed … | Sep 23, 2026 |