Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55204
Total
4355
Critical
16406
High
16086
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-76715 | HIGH | 7.1 | A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-middle (MitM) attack. Successful exploitation of this vulnerability could … | Sep 22, 2026 |
| CVE-2026-76714 | HIGH | 7.2 | Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could … | Sep 22, 2026 |
| CVE-2026-76713 | HIGH | 7.2 | A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an authenticated remote attacker … | Sep 22, 2026 |
| CVE-2026-76712 | HIGH | 7.3 | A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information disclosure, or denial of service. An unauthenticated remote … | Sep 22, 2026 |
| CVE-2026-76711 | HIGH | 7.5 | A vulnerability exists in an Analytics and Location Engine (ALE) component where the impacted process improperly processes incoming socket connections. An unauthenticated remote attacker could … | Sep 22, 2026 |
| CVE-2026-76710 | HIGH | 7.5 | A vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the disclosure of sensitive information. An unauthenticated remote attacker … | Sep 22, 2026 |
| CVE-2026-76709 | CRITICAL | 9.8 | A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an unauthenticated remote attacker … | Sep 22, 2026 |
| CVE-2026-76708 | CRITICAL | 9.8 | A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use default, hard-coded credentials for several administrative and … | Sep 22, 2026 |
| CVE-2026-75432 | UNKNOWN | — | An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive information via the src/scanner.cpp, Scanner::PopIndent(), and Scanner::PushIndentTo() components | Sep 22, 2026 |
| CVE-2026-65829 | MEDIUM | 5.3 | MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0 until 16.5.0, reading … | Sep 22, 2026 |
| CVE-2026-63628 | UNKNOWN | — | mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, the fee-payer cosigning path in src/tempo/internal/fee-payer.ts copied a client-supplied access_list from a 0x78 … | Sep 22, 2026 |
| CVE-2026-63627 | UNKNOWN | — | mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, FeePayerPolicy in src/tempo/internal/fee-payer.ts used decodeFunctionData to validate fee-sponsored calldata but did not reject … | Sep 22, 2026 |
| CVE-2026-63104 | HIGH | 8.1 | Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace members with viewer or member roles to delete and modify tasks … | Sep 22, 2026 |
| CVE-2026-62985 | HIGH | 7.5 | request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior to 3.2.1, RequestFilteringHttpAgent and RequestFilteringHttpsAgent synchronously threw from createConnection when rejecting a … | Sep 22, 2026 |
| CVE-2026-61570 | HIGH | 7.5 | MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 5.5.5 until 16.4.1, MerlinReader … | Sep 22, 2026 |
| CVE-2026-59991 | HIGH | 7.5 | psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.composite() and PSDImage.numpy() allocated output buffers from attacker-controlled PSD header … | Sep 22, 2026 |
| CVE-2026-58268 | HIGH | 7.5 | SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.1, ParserStream.parseSingle in sip/parser_stream.go allocates a SIP body buffer from the … | Sep 22, 2026 |
| CVE-2026-47116 | CRITICAL | 9.8 | LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where the root and guest account passwords are stored in /etc/shadow as weak hashes recoverable with dictionary-based cracking … | Sep 22, 2026 |
| CVE-2026-28325 | HIGH | 8.8 | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is … | Sep 22, 2026 |
| CVE-2026-28324 | CRITICAL | 9.8 | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a … | Sep 22, 2026 |
| CVE-2026-95862 | HIGH | 7.5 | A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of … | Sep 22, 2026 |
| CVE-2026-95861 | HIGH | 7.5 | A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of … | Sep 22, 2026 |
| CVE-2026-95831 | HIGH | 7.8 | Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved … | Sep 22, 2026 |
| CVE-2026-94462 | HIGH | 7.1 | Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5.4, PATCH /api/v3/store/carts/:id/associate in Spree::Api::V3::Store::CartsController#associate uses find_cart_for_association to … | Sep 22, 2026 |
| CVE-2026-91130 | UNKNOWN | — | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity … | Sep 22, 2026 |