Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55204
Total
4355
Critical
16406
High
16086
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-86248 | CRITICAL | 9.8 | CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from … | Sep 23, 2026 |
| CVE-2026-84791 | HIGH | 7.1 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to … | Sep 23, 2026 |
| CVE-2026-84789 | HIGH | 7.1 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to … | Sep 23, 2026 |
| CVE-2026-84787 | HIGH | 8.1 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain … | Sep 23, 2026 |
| CVE-2026-80444 | MEDIUM | 5.4 | URL redirection to untrusted site ('open redirect') vulnerability in Abis Technology Ltd. Co. AVESİS allows Input Data Manipulation. This issue affects AVESİS: from 202608201331 before … | Sep 23, 2026 |
| CVE-2026-79677 | HIGH | 7.5 | Missing release of resource after effective lifetime, Comparison using wrong factors vulnerability in Apache Tomcat allows a denial of service as a result of lost … | Sep 23, 2026 |
| CVE-2026-78437 | HIGH | 7.3 | Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail. This issue … | Sep 23, 2026 |
| CVE-2026-78383 | HIGH | 7.5 | Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauthenticated AJP request to pin an AJP processing thread leading to denial … | Sep 23, 2026 |
| CVE-2026-78253 | UNKNOWN | — | Uncontrolled recursion in QXmlStreamReader::readElementText() in Qt Group Qt allows attackers to cause a denial of service (application crash via stack exhaustion) via a crafted XML … | Sep 23, 2026 |
| CVE-2026-77791 | HIGH | 7.5 | Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS attack. This issue affects Apache Tomcat: from 11.0.0-M5 through … | Sep 23, 2026 |
| CVE-2026-77762 | HIGH | 8.1 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat allows an attacker to inject trailer fields into another HTTP/2 request. … | Sep 23, 2026 |
| CVE-2026-77756 | LOW | 3.7 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat caused by processing the transfer-encoding header for an HTTP/1.0 request may allow an … | Sep 23, 2026 |
| CVE-2026-76183 | CRITICAL | 9.8 | Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affects Apache Tomcat: … | Sep 23, 2026 |
| CVE-2026-75973 | HIGH | 7.3 | Improper Authentication vulnerability in Apache Tomcat. When Jakarta Authentication was configured with SimpleAuthConfigProvider as the default provider and multiple web application used that provider, the … | Sep 23, 2026 |
| CVE-2026-73581 | MEDIUM | 6.5 | Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore. This issue … | Sep 23, 2026 |
| CVE-2026-15358 | HIGH | 7.5 | ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability. | Sep 23, 2026 |
| CVE-2026-14913 | HIGH | 8.8 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vulnerability in Rule Management Search Reports. | Sep 23, 2026 |
| CVE-2026-12370 | HIGH | 7.6 | ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which … | Sep 23, 2026 |
| CVE-2026-96456 | MEDIUM | 6.3 | The Reachy Mini Bluetooth service asks a connecting device for a PIN before it will accept commands. The check protects the session but not the … | Sep 23, 2026 |
| CVE-2026-96455 | HIGH | 8.8 | The Reachy Mini daemon exposes an HTTP API for managing the robot. Its app installation endpoint, POST /apps/install in src/reachy_mini/daemon/app/routers/apps.py, has no authentication. The handler's … | Sep 23, 2026 |
| CVE-2026-96442 | HIGH | 7.8 | A code execution flaw was found in Emacs, affecting versions prior to 31.2. The Flymake mode using language backends other than Lisp would execute arbitrary … | Sep 23, 2026 |
| CVE-2026-90950 | MEDIUM | 5.3 | The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handler when a form field is absent from the … | Sep 23, 2026 |
| CVE-2026-87978 | MEDIUM | 5.3 | The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its payment webhook, allowing unauthenticated attackers to … | Sep 23, 2026 |
| CVE-2026-87848 | LOW | 3.7 | The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any authorisation or authentication on one of its AJAX actions available to unauthenticated users, … | Sep 23, 2026 |
| CVE-2026-87071 | MEDIUM | 5.3 | The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply, and does not exclude the keys WordPress … | Sep 23, 2026 |