Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54999
Total
4345
Critical
16386
High
16069
Medium
CVE ID Severity Score Description Published
CVE-2026-95829 MEDIUM 6.3 A vulnerability was identified in TDuckCloud tduck-platform up to 5.3. This vulnerability affects the function PaginationInnerInterceptor.concatOrderBy of the file tduck-api/src/main/java/com/tduck/cloud/api/config/MybatisPlusConfig.java of the component Pagination Inner … Sep 23, 2026
CVE-2026-94367 HIGH 7.2 OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated administrator can supply crafted backup-area configuration input … Sep 23, 2026
CVE-2026-92930 MEDIUM 6.2 OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other server-side cryptographic material. An … Sep 23, 2026
CVE-2026-92929 MEDIUM 5.3 OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determining the request source address. An unauthenticated … Sep 23, 2026
CVE-2026-92928 MEDIUM 6.5 OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential that cannot be changed, disabled, or rotated. … Sep 23, 2026
CVE-2026-95828 MEDIUM 4.3 A vulnerability was determined in Mstfakts College-Management-System. This affects the function session_start of the file Front-end/server.php of the component Authentication. Executing a manipulation can lead … Sep 22, 2026
CVE-2026-95820 MEDIUM 6.3 A vulnerability was found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php?section=admin1. Performing a manipulation … Sep 22, 2026
CVE-2026-61685 HIGH 7.5 ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list endpoints build TypeORM `QueryBuilder` conditions using unsanitized HTTP query parameter … Sep 22, 2026
CVE-2026-57576 MEDIUM 6.5 plone.app.dexterity is a content-type system for the Plone content management system, and plone.app.contenttypes provides Plone’s Dexterity-based content types. Plone.app.dexterity versions through 3.2.2, 4.0.0 through 4.1.2, … Sep 22, 2026
CVE-2026-18176 HIGH 7.4 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information. Sep 22, 2026
CVE-2026-18173 LOW 3.7 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper enforcement of mutual TLS authentication. Sep 22, 2026
CVE-2026-18172 HIGH 7.4 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity … Sep 22, 2026
CVE-2026-18170 MEDIUM 6.5 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to allocation of resources without … Sep 22, 2026
CVE-2026-18169 CRITICAL 9.9 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links. Sep 22, 2026
CVE-2026-18163 CRITICAL 9.8 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data. Sep 22, 2026
CVE-2026-18162 CRITICAL 9.8 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within … Sep 22, 2026
CVE-2026-95819 HIGH 7.3 A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this vulnerability is an unknown functionality of the file login.php. Such manipulation … Sep 22, 2026
CVE-2026-19202 UNKNOWN — A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and reused across different audiences. … Sep 22, 2026
CVE-2026-18161 MEDIUM 4.3 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to falsify transaction audit logs due to improper validation of a … Sep 22, 2026
CVE-2026-18156 MEDIUM 6.5 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to bypass security controls by forging user identities due to improper … Sep 22, 2026
CVE-2026-18154 HIGH 8.0 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or … Sep 22, 2026
CVE-2026-18153 MEDIUM 5.4 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the … Sep 22, 2026
CVE-2026-18152 HIGH 7.4 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to forge validly-signed messages due to improper verification of cryptographic signatures. Sep 22, 2026
CVE-2026-18137 HIGH 8.1 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization of special elements … Sep 22, 2026
CVE-2026-18134 HIGH 7.5 IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information. Sep 22, 2026