Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54999
Total
4345
Critical
16386
High
16069
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-86677 | HIGH | 8.8 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution. | Sep 23, 2026 |
| CVE-2026-59167 | CRITICAL | 10.0 | SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject … | Sep 23, 2026 |
| CVE-2026-18179 | MEDIUM | 6.5 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions due to improper authorization. | Sep 23, 2026 |
| CVE-2026-18177 | HIGH | 7.1 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks. | Sep 23, 2026 |
| CVE-2026-12974 | UNKNOWN | — | A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW). This issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through … | Sep 23, 2026 |
| CVE-2026-95676 | UNKNOWN | — | A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating … | Sep 23, 2026 |
| CVE-2026-86247 | HIGH | 7.4 | Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirements to be down-graded for some configurations. This issue affects Apache … | Sep 23, 2026 |
| CVE-2026-86246 | CRITICAL | 9.1 | Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX. This … | Sep 23, 2026 |
| CVE-2026-86243 | HIGH | 7.5 | Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue … | Sep 23, 2026 |
| CVE-2026-84091 | MEDIUM | 5.3 | The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a payment notification is genuine before marking … | Sep 23, 2026 |
| CVE-2026-77112 | MEDIUM | 6.5 | Server-Side request forgery (SSRF) vulnerability in Global IT Informatics Technology Services Inc. Weoll allows Server Side Request Forgery. This issue affects Weoll: before 3.2.45.44. | Sep 23, 2026 |
| CVE-2026-76980 | HIGH | 7.4 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vulnerability in the Firewall Analyzer syslog collector. | Sep 23, 2026 |
| CVE-2026-76979 | HIGH | 7.7 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vulnerability in the Rule Tracking Compare Policies feature. | Sep 23, 2026 |
| CVE-2026-76978 | HIGH | 8.8 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection vulnerability in the Diagnose Settings feature. | Sep 23, 2026 |
| CVE-2026-75825 | HIGH | 8.8 | ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability. | Sep 23, 2026 |
| CVE-2026-19599 | CRITICAL | 9.9 | ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module. | Sep 23, 2026 |
| CVE-2026-96446 | MEDIUM | 4.2 | A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent authentication path prompt=none is used, which … | Sep 23, 2026 |
| CVE-2026-96445 | MEDIUM | 6.8 | A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the system evaluates specific … | Sep 23, 2026 |
| CVE-2026-87022 | HIGH | 7.5 | Improper handling of length parameter inconsistency vulnerability in Apache Tomcat allows WebSocket message smuggling when per-message-deflate is used. This issue affects Apache Tomcat: from 11.0.0-M1 … | Sep 23, 2026 |
| CVE-2026-86350 | CRITICAL | 9.1 | Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up. … | Sep 23, 2026 |
| CVE-2026-86248 | CRITICAL | 9.8 | CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from … | Sep 23, 2026 |
| CVE-2026-84791 | HIGH | 7.1 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to … | Sep 23, 2026 |
| CVE-2026-84789 | HIGH | 7.1 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to … | Sep 23, 2026 |
| CVE-2026-84787 | HIGH | 8.1 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain … | Sep 23, 2026 |
| CVE-2026-80444 | MEDIUM | 5.4 | URL redirection to untrusted site ('open redirect') vulnerability in Abis Technology Ltd. Co. AVESİS allows Input Data Manipulation. This issue affects AVESİS: from 202608201331 before … | Sep 23, 2026 |