Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55204
Total
4355
Critical
16406
High
16086
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-76910 | UNKNOWN | — | Unleash is an open-source feature management platform. Prior to 8.0.3, cloneFeatureToggle and POST /api/admin/projects/:projectId/features/:featureName/clone authorize creation in the destination project but do not verify access … | Sep 22, 2026 |
| CVE-2026-76909 | UNKNOWN | — | Unleash is an open-source feature management platform. Prior to 8.0.3, the change-request approval email template at src/mailtemplates/requested-cr-approval/requested-cr-approval.html.mustache renders the user-controlled changeRequestTitle, requesterName, and requesterEmail values … | Sep 22, 2026 |
| CVE-2026-75101 | UNKNOWN | — | An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch … | Sep 22, 2026 |
| CVE-2026-67615 | HIGH | 8.8 | openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability that allows any authenticated non-guest user to execute arbitrary code by exploiting Java deserialization in … | Sep 22, 2026 |
| CVE-2026-62364 | LOW | 2.3 | wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration from .weblate, .weblate.ini, or weblate.ini can select the API … | Sep 22, 2026 |
| CVE-2026-94574 | HIGH | 7.8 | A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\msys64) that is writable … | Sep 22, 2026 |
| CVE-2026-89282 | CRITICAL | 9.1 | The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissions vulnerability through its default install directory on C:\, which … | Sep 22, 2026 |
| CVE-2026-89281 | HIGH | 8.4 | The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution. | Sep 22, 2026 |
| CVE-2026-88624 | CRITICAL | 9.1 | Missing path validation in the Worktree.remove component of openCode v1.18.26 allows attackers to execute arbitrary recursive directory deletion via a crafted payload. | Sep 22, 2026 |
| CVE-2026-88419 | HIGH | 8.8 | An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=thumbUpload) of WuzhiCMS 5.0.0 allows an authenticated low-privileged member to upload a … | Sep 22, 2026 |
| CVE-2026-88418 | UNKNOWN | — | CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-changing admin request, and it does not send … | Sep 22, 2026 |
| CVE-2026-88416 | UNKNOWN | — | MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability in the custom model/form import feature. | Sep 22, 2026 |
| CVE-2026-88350 | UNKNOWN | — | An integer overflow vulnerability exists in MPack 1.1.1 in mpack_node_cstr_alloc() and mpack_node_utf8_cstr_alloc(). | Sep 22, 2026 |
| CVE-2026-88345 | HIGH | 7.5 | An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers schema ends with an unterminated quotation mark, the C-string … | Sep 22, 2026 |
| CVE-2026-88344 | HIGH | 7.5 | An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers schema buffer ends with a digit, the integer digit-scan … | Sep 22, 2026 |
| CVE-2026-88341 | MEDIUM | 5.5 | A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid … | Sep 22, 2026 |
| CVE-2026-88340 | UNKNOWN | — | An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of external-variable … | Sep 22, 2026 |
| CVE-2026-88339 | MEDIUM | 5.5 | A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). The vulnerability occurs when cloning a PROTO default SFImage field with … | Sep 22, 2026 |
| CVE-2026-87121 | CRITICAL | 9.8 | lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device. | Sep 22, 2026 |
| CVE-2026-83805 | MEDIUM | 6.4 | Nautobot is a Network Source of Truth and Network Automation Platform. From 3.0.0 until 3.1.8, the generic ApprovalWorkflowStageResponse create endpoint does not enforce approver-group membership, … | Sep 22, 2026 |
| CVE-2026-83801 | MEDIUM | 5.4 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.37 and 3.1.8, a user with extras.add_relationship or extras.change_relationship permission can store … | Sep 22, 2026 |
| CVE-2026-79767 | MEDIUM | 5.5 | Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143.3, 1.144.2, and 1.145.0, the customverbauthorizer admission plugin's mustCheckProjectMembers … | Sep 22, 2026 |
| CVE-2026-77322 | HIGH | 7.5 | SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go creates a wsutil.Reader without setting MaxFrameSize, allowing … | Sep 22, 2026 |
| CVE-2026-76717 | MEDIUM | 5.3 | A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could … | Sep 22, 2026 |
| CVE-2026-76716 | MEDIUM | 5.3 | Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that may allow for unauthorized access or denial of service. An unauthenticated remote attacker could … | Sep 22, 2026 |