Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55204
Total
4355
Critical
16406
High
16086
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-75655 | HIGH | 7.8 | Bridge is affected by an Uncontrolled Recursion vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could … | Sep 22, 2026 |
| CVE-2026-75649 | HIGH | 7.8 | Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of … | Sep 22, 2026 |
| CVE-2026-75638 | MEDIUM | 6.5 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability … | Sep 22, 2026 |
| CVE-2026-75634 | MEDIUM | 4.3 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability … | Sep 22, 2026 |
| CVE-2026-75633 | MEDIUM | 5.5 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to … | Sep 22, 2026 |
| CVE-2026-75632 | HIGH | 7.5 | CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust … | Sep 22, 2026 |
| CVE-2026-63386 | MEDIUM | 5.3 | js-toml is a TOML parser for JavaScript. Prior to 1.1.3, load() does not bound nesting or dotted-key depth in the recursive parser at src/load/parser.ts or … | Sep 22, 2026 |
| CVE-2026-57149 | CRITICAL | 9.9 | plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of portlets that ship with Plone. Starting in version 5.0.0 and … | Sep 22, 2026 |
| CVE-2026-48361 | MEDIUM | 6.1 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form … | Sep 22, 2026 |
| CVE-2026-37604 | CRITICAL | 9.8 | pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP address in _protected/framework/Ip/Ip.class.php from the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers without verifying the request … | Sep 22, 2026 |
| CVE-2026-37603 | UNKNOWN | — | Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0. The CAPTCHA escalation flag is stored … | Sep 22, 2026 |
| CVE-2026-34689 | HIGH | 8.6 | Adobe Connect is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system … | Sep 22, 2026 |
| CVE-2026-19480 | HIGH | 7.5 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability … | Sep 22, 2026 |
| CVE-2026-95660 | MEDIUM | 6.3 | A security flaw has been discovered in Moonshot AI Kimi Code up to 0.31.0. The affected element is an unknown function of the file agent-core-v2/src/agent/mcp/config-loader.ts … | Sep 22, 2026 |
| CVE-2026-95657 | LOW | 3.5 | A vulnerability was determined in dgtlmoon Changedetection.io up to 0.55.8. This issue affects the function setCurrentSelectedText of the file changedetectionio/static/js/visual-selector.js of the component Visual Selector. … | Sep 22, 2026 |
| CVE-2026-95656 | HIGH | 7.3 | A vulnerability was found in dgtlmoon changedetection.io up to 50389b07. This vulnerability affects the function add_watch_ui_snapshot of the file changedetectionio/blueprint/add_watch_ui/__init__.py of the component Preview Endpoint. … | Sep 22, 2026 |
| CVE-2026-95624 | MEDIUM | 6.8 | The Tauri updater plugin's 'check' IPC command accepts an allowDowngrades boolean parameter directly from frontend JavaScript code. When set to true, it replaces the version … | Sep 22, 2026 |
| CVE-2026-94384 | HIGH | 8.1 | Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26 allows any IAM principal with lambda:InvokeFunction permission on the affected function to escalate privileges and perform AWS API … | Sep 22, 2026 |
| CVE-2026-93345 | HIGH | 7.5 | MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker … | Sep 22, 2026 |
| CVE-2026-8849 | UNKNOWN | — | Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation. This issue affects Connext Professional: from 7.6.0 before 7.7.0.1. | Sep 22, 2026 |
| CVE-2026-89276 | CRITICAL | 9.9 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in … | Sep 22, 2026 |
| CVE-2026-89275 | CRITICAL | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in … | Sep 22, 2026 |
| CVE-2026-86056 | MEDIUM | 5.5 | Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the NPPM_SAVESESSION handler in PowerEditor/src/NppBigSwitch.cpp converts lParam to a sessionInfo pointer and dereferences … | Sep 22, 2026 |
| CVE-2026-86054 | HIGH | 7.8 | Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in NppParameters::writeSession in PowerEditor/src/Parameters.cpp because it copies … | Sep 22, 2026 |
| CVE-2026-85995 | HIGH | 7.3 | Notepad++ is a free and open-source source code editor. From 8.9.7 until 8.9.8, the Notepad++ updater and signature verification path can accept a modified GUP.exe … | Sep 22, 2026 |