Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

55204
Total
4355
Critical
16406
High
16086
Medium
CVE ID Severity Score Description Published
CVE-2026-91129 MEDIUM 5.4 Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP integration automatically processed unauthenticated _ipp._tcp.local mDNS … Sep 22, 2026
CVE-2026-89277 MEDIUM 5.5 CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability … Sep 22, 2026
CVE-2026-88415 HIGH 8.7 MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site Scripting (XSS). The article content field `contentDetails` is excluded from the global XSS filter. Sep 22, 2026
CVE-2026-88414 UNKNOWN — MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the PageAction.verify endpoint (GET /ms/mdiy/page/verify.do). Sep 22, 2026
CVE-2026-84396 MEDIUM 5.5 InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash … Sep 22, 2026
CVE-2026-84395 HIGH 7.1 Premiere Pro is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation potentially resulting in unauthorized write access. Exploitation of … Sep 22, 2026
CVE-2026-83964 MEDIUM 6.2 Adobe Connect is affected by an Improper Certificate Validation vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to … Sep 22, 2026
CVE-2026-83963 HIGH 7.8 Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation … Sep 22, 2026
CVE-2026-83962 HIGH 7.8 Substance3D - Modeler is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. … Sep 22, 2026
CVE-2026-82000 CRITICAL 9.6 Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit … Sep 22, 2026
CVE-2026-81999 HIGH 8.7 Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. An attacker with high privileges … Sep 22, 2026
CVE-2026-81998 HIGH 7.8 Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation … Sep 22, 2026
CVE-2026-81995 CRITICAL 9.1 Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the … Sep 22, 2026
CVE-2026-79906 HIGH 7.8 Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation … Sep 22, 2026
CVE-2026-77558 HIGH 7.5 A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of … Sep 22, 2026
CVE-2026-77556 HIGH 7.5 A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of … Sep 22, 2026
CVE-2026-77555 HIGH 7.5 A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of … Sep 22, 2026
CVE-2026-77544 HIGH 7.5 A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of … Sep 22, 2026
CVE-2026-77399 MEDIUM 6.5 icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 6.1.0 until 7.2.2, vInt.from_ical accepts an attacker-controlled VALARM REPEAT value … Sep 22, 2026
CVE-2026-77272 MEDIUM 5.4 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth error query parameter is passed … Sep 22, 2026
CVE-2026-77269 MEDIUM 6.5 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the remediation for CVE-2026-27825 protects download destinations … Sep 22, 2026
CVE-2026-77268 MEDIUM 5.5 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth fallback token directory and JSON … Sep 22, 2026
CVE-2026-77266 MEDIUM 6.5 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment accepts absolute paths and traversal sequences … Sep 22, 2026
CVE-2026-77262 HIGH 8.6 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment accepts an attacker-controlled file_path and does … Sep 22, 2026
CVE-2026-77259 HIGH 7.7 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment opens a caller-selected server-local file without … Sep 22, 2026