Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55255
Total
4360
Critical
16420
High
16093
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-95654 | HIGH | 7.4 | Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization decision without re-checking token validity during acceptance. Attackers with a … | Sep 22, 2026 |
| CVE-2026-95653 | HIGH | 7.5 | Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable. Unauthenticated attackers can … | Sep 22, 2026 |
| CVE-2026-94640 | HIGH | 7.5 | A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number … | Sep 22, 2026 |
| CVE-2026-92706 | LOW | 3.4 | Dark Reader is an accessibility browser extension that makes web pages colors dark. Prior to 4.9.126, a website can cause the browser extension's image inversion … | Sep 22, 2026 |
| CVE-2026-90462 | MEDIUM | 5.4 | A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP … | Sep 22, 2026 |
| CVE-2026-88010 | UNKNOWN | — | Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.7.13, checkPassword in pkg/middlewares/auth/basic_auth.go constructs the BasicAuth singleflight key from the … | Sep 22, 2026 |
| CVE-2026-86805 | MEDIUM | 6.3 | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local … | Sep 22, 2026 |
| CVE-2026-86698 | UNKNOWN | — | Insufficient Session Expiration vulnerability in OAuth token issuance in hexpm hexpm allows a user whose organization membership or session has ended to keep reading the … | Sep 22, 2026 |
| CVE-2026-85055 | UNKNOWN | — | Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.22.0, field-level read permission is enforced on selected output fields but not on GraphQL … | Sep 22, 2026 |
| CVE-2026-81886 | MEDIUM | 5.5 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit crash-dump dmp64 parser was vulnerable because the Windows dmp64 … | Sep 22, 2026 |
| CVE-2026-81885 | MEDIUM | 5.5 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's NE relocation fixup-chain parser was vulnerable because the NE relocation parser … | Sep 22, 2026 |
| CVE-2026-81884 | LOW | 2.5 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O LC_DATA_IN_CODE parser was vulnerable because the Mach-O LC_DATA_IN_CODE parser trusted … | Sep 22, 2026 |
| CVE-2026-81883 | LOW | 3.3 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Lua 5.3 bytecode function parser was vulnerable because the Lua 5.3 … | Sep 22, 2026 |
| CVE-2026-81882 | LOW | 3.3 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's binary property-list Unicode parser was vulnerable because the binary-property-list Unicode parser … | Sep 22, 2026 |
| CVE-2026-81881 | LOW | 3.3 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field … | Sep 22, 2026 |
| CVE-2026-81880 | MEDIUM | 5.5 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Apple Preferred Executable Format loader was vulnerable because the PEF loader … | Sep 22, 2026 |
| CVE-2026-81879 | MEDIUM | 5.5 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's ELF PN_XNUM handling was vulnerable because the ELF parser allocated the … | Sep 22, 2026 |
| CVE-2026-81878 | MEDIUM | 5.5 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecode .pyc marshal parser was vulnerable because the CPython marshal … | Sep 22, 2026 |
| CVE-2026-80156 | CRITICAL | 9.1 | Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a path traversal vulnerability in the web management portal … | Sep 22, 2026 |
| CVE-2026-80155 | CRITICAL | 10.0 | Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain an authentication bypass vulnerability in the web management portal … | Sep 22, 2026 |
| CVE-2026-80154 | CRITICAL | 9.6 | All firmware versions of Lantronix SLC8000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated … | Sep 22, 2026 |
| CVE-2026-80152 | CRITICAL | 9.1 | Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with … | Sep 22, 2026 |
| CVE-2026-80151 | CRITICAL | 9.1 | Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with … | Sep 22, 2026 |
| CVE-2026-80150 | HIGH | 7.5 | Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener … | Sep 22, 2026 |
| CVE-2026-80149 | HIGH | 8.6 | Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener … | Sep 22, 2026 |