Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55714
Total
4403
Critical
16544
High
16275
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-61784 | MEDIUM | 6.1 | xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, trusted HTML. Versions prior to 0.4.3 do not HTML-entity-encode attribute values … | Sep 24, 2026 |
| CVE-2026-61782 | HIGH | 7.5 | Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to version 1.5.16, the default Rsdoctor report HTTP server started by `@rsdoctor/rspack-plugin` binds … | Sep 24, 2026 |
| CVE-2026-61742 | UNKNOWN | — | DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose an unauthenticated HTTP MCP endpoint when … | Sep 24, 2026 |
| CVE-2026-61741 | CRITICAL | 9.3 | http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` without … | Sep 24, 2026 |
| CVE-2026-61732 | CRITICAL | 10.0 | Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of agent reconnaissance against target … | Sep 24, 2026 |
| CVE-2026-61604 | UNKNOWN | — | The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds module moved funds from … | Sep 24, 2026 |
| CVE-2026-57179 | MEDIUM | 4.2 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it … | Sep 24, 2026 |
| CVE-2026-57178 | HIGH | 7.4 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature … | Sep 24, 2026 |
| CVE-2026-57177 | MEDIUM | 4.3 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications … | Sep 24, 2026 |
| CVE-2026-57176 | MEDIUM | 6.8 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth … | Sep 24, 2026 |
| CVE-2026-57175 | MEDIUM | 6.4 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without … | Sep 24, 2026 |
| CVE-2026-54461 | MEDIUM | 6.5 | Habitica is a habit tracker application that treats goals like a role-playing game. From 4.172.1 until 5.48.2, a query parameter on Habitica's /api/v3/groups/:groupId/members route is … | Sep 24, 2026 |
| CVE-2026-97521 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: gfs2: fix quota init duplicate scan gfs2_quota_init() checks for duplicate quota_change IDs while holding qd_lock … | Sep 24, 2026 |
| CVE-2026-97520 | HIGH | 7.1 | In the Linux kernel, the following vulnerability has been resolved: gfs2: move quota_init qc iterator increment Move qc++ from the loop body into the for-loop … | Sep 24, 2026 |
| CVE-2026-97519 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix null pointer dereference in devcoredump cleanup In xe_devcoredump_snapshot_free(), ss->gt may be NULL when … | Sep 24, 2026 |
| CVE-2026-97518 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: reject duplicate wiphy cipher suite entries Duplicate entries in wiphy->cipher_suites do not describe … | Sep 24, 2026 |
| CVE-2026-97517 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: reject beacons with bad HE operation The HE operation element not only needs … | Sep 24, 2026 |
| CVE-2026-97516 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Add NULL check for chip->edcca_th in rtw_fw_adaptivity_result() It was recently reported that rtw_fw_adaptivity_result() … | Sep 24, 2026 |
| CVE-2026-97515 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: i3c: master: svc: Prevent IRQ storm from false SLVSTART on NPCM845 On NPCM845, when a … | Sep 24, 2026 |
| CVE-2026-97514 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Fix Reports from Kernel Lock Validator handle_dynamic_resolution change requires that the state_lock … | Sep 24, 2026 |
| CVE-2026-97513 | HIGH | 7.8 | In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Release m2m_ctx after Instance Removed from List Possible use after free if … | Sep 24, 2026 |
| CVE-2026-97512 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: spi: spi-qcom-qspi: Fix incomplete error handling in runtime PM The runtime PM functions had incomplete … | Sep 24, 2026 |
| CVE-2026-97511 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: avoid out-of-bounds access in monitor In NAN, we don't know on what band … | Sep 24, 2026 |
| CVE-2026-97510 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Release request if tb_cfg_request() fails in __tb_xdomain_response() If tb_cfg_request() fails setting up the request … | Sep 24, 2026 |
| CVE-2026-97509 | HIGH | 8.8 | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Keep XDomain reference during the lifetime of a service This is needed because we … | Sep 24, 2026 |