Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54999
Total
4345
Critical
16386
High
16069
Medium
CVE ID Severity Score Description Published
CVE-2026-92164 MEDIUM 6.5 Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.6.0, HTTPSession mounts a FileAdapter for the … Sep 23, 2026
CVE-2026-88974 MEDIUM 5.4 WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post … Sep 23, 2026
CVE-2026-73858 MEDIUM 5.3 Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. From 5.0.0 through 5.10.13, submitted values from public Freeform forms can be … Sep 23, 2026
CVE-2026-73591 HIGH 7.5 Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Information in Source Code vulnerability. An unauthenticated attacker with … Sep 23, 2026
CVE-2026-73589 MEDIUM 6.3 Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak Encoding for Password vulnerability. A low privileged … Sep 23, 2026
CVE-2026-73588 HIGH 7.4 Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access … Sep 23, 2026
CVE-2026-73587 MEDIUM 6.8 Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could … Sep 23, 2026
CVE-2026-73586 MEDIUM 6.4 Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with adjacent network access … Sep 23, 2026
CVE-2026-71178 LOW 3.7 Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization Decisions vulnerability. An unauthenticated attacker … Sep 23, 2026
CVE-2026-71177 MEDIUM 5.4 Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. A low privileged … Sep 23, 2026
CVE-2026-63002 MEDIUM 4.8 REDAXO is a PHP-based content management system. Prior to 5.21.2, redaxo/src/addons/mediapool/pages/sync.php inserts filenames held in $diffFiles from the media filesystem into the Mediapool Sync page … Sep 23, 2026
CVE-2026-63001 MEDIUM 4.8 REDAXO is a PHP-based content management system. Prior to 5.21.2, the mediaIsInUse() handler in redaxo/src/addons/media_manager/lib/media_manager.php inserts a Media Manager type name into raw backend warning … Sep 23, 2026
CVE-2026-63000 MEDIUM 6.4 REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_api_install_package_update in redaxo/src/addons/install/lib/api/api_package_update.php inherits the false default from rex_api_function::requiresCsrfProtection() instead of requiring a CSRF token. … Sep 23, 2026
CVE-2026-62998 MEDIUM 4.3 REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_list::getSortColumn() in redaxo/src/core/lib/list.php accepts the sort request parameter without checking whether setColumnSortable() registered the requested … Sep 23, 2026
CVE-2026-61834 MEDIUM 4.3 scim-patch is a library for applying SCIM patch operations. Prior to 0.9.2, navigate() reads inherited properties and assign() uses prototype-chain membership checks while resolving attacker-controlled … Sep 23, 2026
CVE-2026-61413 MEDIUM 6.8 Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could … Sep 23, 2026
CVE-2026-55610 HIGH 8.7 InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.4.1, in InvoiceShelf's … Sep 23, 2026
CVE-2026-96560 CRITICAL 9.8 LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauthenticated RPyC control channel … Sep 23, 2026
CVE-2026-96559 UNKNOWN — Rejected reason: This ID was for testing Sep 23, 2026
CVE-2026-96512 HIGH 7.8 A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, … Sep 23, 2026
CVE-2026-86708 CRITICAL 10.0 ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which … Sep 23, 2026
CVE-2026-86683 HIGH 8.1 ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings. Sep 23, 2026
CVE-2026-86681 HIGH 7.6 ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on … Sep 23, 2026
CVE-2026-86679 HIGH 7.1 ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside … Sep 23, 2026
CVE-2026-86678 HIGH 8.8 ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions. Sep 23, 2026