Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55204
Total
4355
Critical
16406
High
16086
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-85288 | MEDIUM | 6.7 | Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ incompletely enforces shortcuts.xml HMAC validation because WM_MACRODLGRUNMACRO, the Run a Macro Multiple … | Sep 22, 2026 |
| CVE-2026-85279 | HIGH | 8.6 | Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in PluginsManager::loadPluginFromPath in PowerEditor/src/MISC/PluginsManager/PluginsManager.cpp because the plugin-supplied … | Sep 22, 2026 |
| CVE-2026-84412 | CRITICAL | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in … | Sep 22, 2026 |
| CVE-2026-83660 | CRITICAL | 9.9 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not … | Sep 22, 2026 |
| CVE-2026-83597 | HIGH | 7.0 | Netdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent MSI repair launches powershell.exe and wevtutil.exe as elevated interactive processes … | Sep 22, 2026 |
| CVE-2026-82443 | CRITICAL | 9.6 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this … | Sep 22, 2026 |
| CVE-2026-82013 | CRITICAL | 9.9 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this … | Sep 22, 2026 |
| CVE-2026-82011 | CRITICAL | 9.1 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in … | Sep 22, 2026 |
| CVE-2026-82010 | CRITICAL | 9.9 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in … | Sep 22, 2026 |
| CVE-2026-82009 | CRITICAL | 9.1 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in … | Sep 22, 2026 |
| CVE-2026-82008 | CRITICAL | 9.9 | Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current … | Sep 22, 2026 |
| CVE-2026-82003 | HIGH | 8.5 | Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current … | Sep 22, 2026 |
| CVE-2026-7866 | UNKNOWN | — | Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before … | Sep 22, 2026 |
| CVE-2026-77605 | HIGH | 7.8 | Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the Folder as Workspace Run by system action in Notepad++ can resolve a … | Sep 22, 2026 |
| CVE-2026-77274 | UNKNOWN | — | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_url_for_ssrf has a backslash authority confusion because … | Sep 22, 2026 |
| CVE-2026-77271 | UNKNOWN | — | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_safe_path defaults its base directory to os.getcwd(), … | Sep 22, 2026 |
| CVE-2026-77270 | MEDIUM | 6.5 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira and Confluence attachment upload tools … | Sep 22, 2026 |
| CVE-2026-77267 | UNKNOWN | — | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url headers are processed … | Sep 22, 2026 |
| CVE-2026-77265 | MEDIUM | 5.9 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, header-supplied Jira or Confluence URLs are resolved … | Sep 22, 2026 |
| CVE-2026-77261 | HIGH | 7.1 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, _make_ssrf_safe_hook is omitted from JiraFetcher and ConfluenceFetcher … | Sep 22, 2026 |
| CVE-2026-77260 | UNKNOWN | — | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Confluence and Jira upload_attachment implementations accept … | Sep 22, 2026 |
| CVE-2026-77258 | HIGH | 7.7 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment in src/mcp_atlassian/confluence/attachments.py accepts a caller-controlled file_path … | Sep 22, 2026 |
| CVE-2026-77252 | MEDIUM | 6.5 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, caller-supplied projects_filter and spaces_filter arguments can replace … | Sep 22, 2026 |
| CVE-2026-77251 | UNKNOWN | — | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira search accepts a forbidden project clause … | Sep 22, 2026 |
| CVE-2026-77250 | MEDIUM | 6.1 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, OAuthConfig writes a plaintext fallback file containing … | Sep 22, 2026 |