Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54999
Total
4345
Critical
16386
High
16069
Medium
CVE ID Severity Score Description Published
CVE-2026-55456 UNKNOWN — Rejected reason: This CVE is a duplicate of another CVE. Sep 23, 2026
CVE-2026-52744 UNKNOWN — GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API at /go/api/internal/pipelines/**/upstream does not adequately authorize access to … Sep 23, 2026
CVE-2026-91775 UNKNOWN — LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface. Sep 23, 2026
CVE-2026-88840 MEDIUM 5.3 BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message. Sep 23, 2026
CVE-2026-88839 MEDIUM 6.7 BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers. Sep 23, 2026
CVE-2026-88837 MEDIUM 6.5 BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check. Sep 23, 2026
CVE-2026-88835 MEDIUM 6.1 BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read. Sep 23, 2026
CVE-2026-88831 MEDIUM 5.3 BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no … Sep 23, 2026
CVE-2026-86938 HIGH 7.3 A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code with elevated administrator privileges by placing … Sep 23, 2026
CVE-2026-86934 CRITICAL 9.1 An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing … Sep 23, 2026
CVE-2026-86930 CRITICAL 9.1 An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process … Sep 23, 2026
CVE-2026-86926 HIGH 7.8 A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, … Sep 23, 2026
CVE-2026-86867 MEDIUM 6.5 Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities due to incorrect authorization and improper access controls. There are … Sep 23, 2026
CVE-2026-18944 UNKNOWN — Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-18944. Reason: This candidate is a reservation duplicate of CVE-2026-18944. Notes: All CVE … Sep 23, 2026
CVE-2026-96808 HIGH 7.4 In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivileged callers, validated file paths by rejecting literal .. … Sep 23, 2026
CVE-2026-96807 MEDIUM 4.0 In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_ld_cache to write files at an arbitrary location. The filenames … Sep 23, 2026
CVE-2026-96804 HIGH 8.8 MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control entirely in _load_model(), which allows a remote attacker to execute arbitrary code via … Sep 23, 2026
CVE-2026-96775 HIGH 8.8 MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which allows a remote attacker to execute … Sep 23, 2026
CVE-2026-96759 CRITICAL 9.8 orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator options metadata objects. Attackers can inject arbitrary JavaScript … Sep 23, 2026
CVE-2026-96758 CRITICAL 9.8 orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals. Attackers … Sep 23, 2026
CVE-2026-96757 CRITICAL 9.8 orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code. Attackers can inject JavaScript through … Sep 23, 2026
CVE-2026-96756 HIGH 8.1 orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to escape date default values in new Date() calls. … Sep 23, 2026
CVE-2026-96755 CRITICAL 9.8 orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts OpenAPI schema defaults into template literals. Attackers can inject … Sep 23, 2026
CVE-2026-96754 CRITICAL 9.8 orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI path values in single-quoted route literals. Attackers … Sep 23, 2026
CVE-2026-96656 HIGH 7.2 Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The preference TranscoderH264Options is appended verbatim … Sep 23, 2026