Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54999
Total
4345
Critical
16386
High
16069
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-95829 | MEDIUM | 6.3 | A vulnerability was identified in TDuckCloud tduck-platform up to 5.3. This vulnerability affects the function PaginationInnerInterceptor.concatOrderBy of the file tduck-api/src/main/java/com/tduck/cloud/api/config/MybatisPlusConfig.java of the component Pagination Inner … | Sep 23, 2026 |
| CVE-2026-94367 | HIGH | 7.2 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated administrator can supply crafted backup-area configuration input … | Sep 23, 2026 |
| CVE-2026-92930 | MEDIUM | 6.2 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other server-side cryptographic material. An … | Sep 23, 2026 |
| CVE-2026-92929 | MEDIUM | 5.3 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determining the request source address. An unauthenticated … | Sep 23, 2026 |
| CVE-2026-92928 | MEDIUM | 6.5 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential that cannot be changed, disabled, or rotated. … | Sep 23, 2026 |
| CVE-2026-95828 | MEDIUM | 4.3 | A vulnerability was determined in Mstfakts College-Management-System. This affects the function session_start of the file Front-end/server.php of the component Authentication. Executing a manipulation can lead … | Sep 22, 2026 |
| CVE-2026-95820 | MEDIUM | 6.3 | A vulnerability was found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php?section=admin1. Performing a manipulation … | Sep 22, 2026 |
| CVE-2026-61685 | HIGH | 7.5 | ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list endpoints build TypeORM `QueryBuilder` conditions using unsanitized HTTP query parameter … | Sep 22, 2026 |
| CVE-2026-57576 | MEDIUM | 6.5 | plone.app.dexterity is a content-type system for the Plone content management system, and plone.app.contenttypes provides Plone’s Dexterity-based content types. Plone.app.dexterity versions through 3.2.2, 4.0.0 through 4.1.2, … | Sep 22, 2026 |
| CVE-2026-18176 | HIGH | 7.4 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information. | Sep 22, 2026 |
| CVE-2026-18173 | LOW | 3.7 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper enforcement of mutual TLS authentication. | Sep 22, 2026 |
| CVE-2026-18172 | HIGH | 7.4 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity … | Sep 22, 2026 |
| CVE-2026-18170 | MEDIUM | 6.5 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to allocation of resources without … | Sep 22, 2026 |
| CVE-2026-18169 | CRITICAL | 9.9 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links. | Sep 22, 2026 |
| CVE-2026-18163 | CRITICAL | 9.8 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data. | Sep 22, 2026 |
| CVE-2026-18162 | CRITICAL | 9.8 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within … | Sep 22, 2026 |
| CVE-2026-95819 | HIGH | 7.3 | A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this vulnerability is an unknown functionality of the file login.php. Such manipulation … | Sep 22, 2026 |
| CVE-2026-19202 | UNKNOWN | — | A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and reused across different audiences. … | Sep 22, 2026 |
| CVE-2026-18161 | MEDIUM | 4.3 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to falsify transaction audit logs due to improper validation of a … | Sep 22, 2026 |
| CVE-2026-18156 | MEDIUM | 6.5 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to bypass security controls by forging user identities due to improper … | Sep 22, 2026 |
| CVE-2026-18154 | HIGH | 8.0 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or … | Sep 22, 2026 |
| CVE-2026-18153 | MEDIUM | 5.4 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the … | Sep 22, 2026 |
| CVE-2026-18152 | HIGH | 7.4 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to forge validly-signed messages due to improper verification of cryptographic signatures. | Sep 22, 2026 |
| CVE-2026-18137 | HIGH | 8.1 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization of special elements … | Sep 22, 2026 |
| CVE-2026-18134 | HIGH | 7.5 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information. | Sep 22, 2026 |