Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54999
Total
4345
Critical
16386
High
16069
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-92164 | MEDIUM | 6.5 | Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.6.0, HTTPSession mounts a FileAdapter for the … | Sep 23, 2026 |
| CVE-2026-88974 | MEDIUM | 5.4 | WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post … | Sep 23, 2026 |
| CVE-2026-73858 | MEDIUM | 5.3 | Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. From 5.0.0 through 5.10.13, submitted values from public Freeform forms can be … | Sep 23, 2026 |
| CVE-2026-73591 | HIGH | 7.5 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Information in Source Code vulnerability. An unauthenticated attacker with … | Sep 23, 2026 |
| CVE-2026-73589 | MEDIUM | 6.3 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak Encoding for Password vulnerability. A low privileged … | Sep 23, 2026 |
| CVE-2026-73588 | HIGH | 7.4 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access … | Sep 23, 2026 |
| CVE-2026-73587 | MEDIUM | 6.8 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could … | Sep 23, 2026 |
| CVE-2026-73586 | MEDIUM | 6.4 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with adjacent network access … | Sep 23, 2026 |
| CVE-2026-71178 | LOW | 3.7 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization Decisions vulnerability. An unauthenticated attacker … | Sep 23, 2026 |
| CVE-2026-71177 | MEDIUM | 5.4 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. A low privileged … | Sep 23, 2026 |
| CVE-2026-63002 | MEDIUM | 4.8 | REDAXO is a PHP-based content management system. Prior to 5.21.2, redaxo/src/addons/mediapool/pages/sync.php inserts filenames held in $diffFiles from the media filesystem into the Mediapool Sync page … | Sep 23, 2026 |
| CVE-2026-63001 | MEDIUM | 4.8 | REDAXO is a PHP-based content management system. Prior to 5.21.2, the mediaIsInUse() handler in redaxo/src/addons/media_manager/lib/media_manager.php inserts a Media Manager type name into raw backend warning … | Sep 23, 2026 |
| CVE-2026-63000 | MEDIUM | 6.4 | REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_api_install_package_update in redaxo/src/addons/install/lib/api/api_package_update.php inherits the false default from rex_api_function::requiresCsrfProtection() instead of requiring a CSRF token. … | Sep 23, 2026 |
| CVE-2026-62998 | MEDIUM | 4.3 | REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_list::getSortColumn() in redaxo/src/core/lib/list.php accepts the sort request parameter without checking whether setColumnSortable() registered the requested … | Sep 23, 2026 |
| CVE-2026-61834 | MEDIUM | 4.3 | scim-patch is a library for applying SCIM patch operations. Prior to 0.9.2, navigate() reads inherited properties and assign() uses prototype-chain membership checks while resolving attacker-controlled … | Sep 23, 2026 |
| CVE-2026-61413 | MEDIUM | 6.8 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could … | Sep 23, 2026 |
| CVE-2026-55610 | HIGH | 8.7 | InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.4.1, in InvoiceShelf's … | Sep 23, 2026 |
| CVE-2026-96560 | CRITICAL | 9.8 | LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauthenticated RPyC control channel … | Sep 23, 2026 |
| CVE-2026-96559 | UNKNOWN | — | Rejected reason: This ID was for testing | Sep 23, 2026 |
| CVE-2026-96512 | HIGH | 7.8 | A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, … | Sep 23, 2026 |
| CVE-2026-86708 | CRITICAL | 10.0 | ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which … | Sep 23, 2026 |
| CVE-2026-86683 | HIGH | 8.1 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings. | Sep 23, 2026 |
| CVE-2026-86681 | HIGH | 7.6 | ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on … | Sep 23, 2026 |
| CVE-2026-86679 | HIGH | 7.1 | ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside … | Sep 23, 2026 |
| CVE-2026-86678 | HIGH | 8.8 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions. | Sep 23, 2026 |