Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

55204
Total
4355
Critical
16406
High
16086
Medium
CVE ID Severity Score Description Published
CVE-2026-86248 CRITICAL 9.8 CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from … Sep 23, 2026
CVE-2026-84791 HIGH 7.1 ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to … Sep 23, 2026
CVE-2026-84789 HIGH 7.1 ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to … Sep 23, 2026
CVE-2026-84787 HIGH 8.1 ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain … Sep 23, 2026
CVE-2026-80444 MEDIUM 5.4 URL redirection to untrusted site ('open redirect') vulnerability in Abis Technology Ltd. Co. AVESİS allows Input Data Manipulation. This issue affects AVESİS: from 202608201331 before … Sep 23, 2026
CVE-2026-79677 HIGH 7.5 Missing release of resource after effective lifetime, Comparison using wrong factors vulnerability in Apache Tomcat allows a denial of service as a result of lost … Sep 23, 2026
CVE-2026-78437 HIGH 7.3 Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail. This issue … Sep 23, 2026
CVE-2026-78383 HIGH 7.5 Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauthenticated AJP request to pin an AJP processing thread leading to denial … Sep 23, 2026
CVE-2026-78253 UNKNOWN — Uncontrolled recursion in QXmlStreamReader::readElementText() in Qt Group Qt allows attackers to cause a denial of service (application crash via stack exhaustion) via a crafted XML … Sep 23, 2026
CVE-2026-77791 HIGH 7.5 Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS attack. This issue affects Apache Tomcat: from 11.0.0-M5 through … Sep 23, 2026
CVE-2026-77762 HIGH 8.1 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat allows an attacker to inject trailer fields into another HTTP/2 request. … Sep 23, 2026
CVE-2026-77756 LOW 3.7 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat caused by processing the transfer-encoding header for an HTTP/1.0 request may allow an … Sep 23, 2026
CVE-2026-76183 CRITICAL 9.8 Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affects Apache Tomcat: … Sep 23, 2026
CVE-2026-75973 HIGH 7.3 Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured with SimpleAuthConfigProvider as the default provider and multiple web application used that provider, the … Sep 23, 2026
CVE-2026-73581 MEDIUM 6.5 Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore. This issue … Sep 23, 2026
CVE-2026-15358 HIGH 7.5 ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability. Sep 23, 2026
CVE-2026-14913 HIGH 8.8 ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vulnerability in Rule Management Search Reports. Sep 23, 2026
CVE-2026-12370 HIGH 7.6 ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which … Sep 23, 2026
CVE-2026-96456 MEDIUM 6.3 The Reachy Mini Bluetooth service asks a connecting device for a PIN before it will accept commands. The check protects the session but not the … Sep 23, 2026
CVE-2026-96455 HIGH 8.8 The Reachy Mini daemon exposes an HTTP API for managing the robot. Its app installation endpoint, POST /apps/install in src/reachy_mini/daemon/app/routers/apps.py, has no authentication. The handler's … Sep 23, 2026
CVE-2026-96442 HIGH 7.8 A code execution flaw was found in Emacs, affecting versions prior to 31.2. The Flymake mode using language backends other than Lisp would execute arbitrary … Sep 23, 2026
CVE-2026-90950 MEDIUM 5.3 The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handler when a form field is absent from the … Sep 23, 2026
CVE-2026-87978 MEDIUM 5.3 The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its payment webhook, allowing unauthenticated attackers to … Sep 23, 2026
CVE-2026-87848 LOW 3.7 The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any authorisation or authentication on one of its AJAX actions available to unauthenticated users, … Sep 23, 2026
CVE-2026-87071 MEDIUM 5.3 The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply, and does not exclude the keys WordPress … Sep 23, 2026