Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

55255
Total
4360
Critical
16420
High
16093
Medium
CVE ID Severity Score Description Published
CVE-2026-95698 UNKNOWN — The findOrgImage method in MISP's OrgImgHelper constructs a filesystem path by concatenating a user-supplied organization identifier with a fixed image directory and a file extension, … Sep 22, 2026
CVE-2026-95697 UNKNOWN — MISP contains an authorization flaw in the Organisation model's captureOrg method. When the $force parameter is set to true, the method unconditionally overwrites organization metadata … Sep 22, 2026
CVE-2026-95693 UNKNOWN — In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), mime_content_type(), and exif_imagetype() on the supplied path before verifying that the … Sep 22, 2026
CVE-2026-95685 UNKNOWN — MISP contains an access control flaw in the EventReports functionality. The replaceSuggestionInReport action, which allows modification of suggestion content within an event report, was incorrectly … Sep 22, 2026
CVE-2026-95683 UNKNOWN — In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes. The enrichment logic fetched the report using … Sep 22, 2026
CVE-2026-95501 MEDIUM 4.3 A vulnerability was found in mtrano APENCMS up to 6546096d354153309693efabb9a0d824628ed4f5. The affected element is the function eval of the file cms/weasel.php of the component Template … Sep 22, 2026
CVE-2026-95500 HIGH 7.3 A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.php of the component Save Handler. … Sep 22, 2026
CVE-2026-94570 MEDIUM 5.9 SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decode worker, which enables an unauthenticated remote attacker … Sep 22, 2026
CVE-2026-94127 CRITICAL 9.8 When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution … Sep 22, 2026
CVE-2026-93344 MEDIUM 6.5 MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_get_page_content AJAX action that allows authenticated attackers with subscriber-level access or higher … Sep 22, 2026
CVE-2026-93088 CRITICAL 9.8 SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network … Sep 22, 2026
CVE-2026-89407 HIGH 7.5 NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers … Sep 22, 2026
CVE-2026-84388 CRITICAL 9.6 A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may … Sep 22, 2026
CVE-2026-79315 MEDIUM 4.7 A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The management interface reflects the raw request URI into a client-side template binding expression used for … Sep 22, 2026
CVE-2026-79314 UNKNOWN — A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, protocol, … Sep 22, 2026
CVE-2026-79313 CRITICAL 9.8 webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead of checking the last-access … Sep 22, 2026
CVE-2026-65179 HIGH 8.8 NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation. A successful exploit of … Sep 22, 2026
CVE-2026-65178 HIGH 7.8 NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a maliciously crafted model_config.yaml can inject unsafe parameters. A successful exploit of this vulnerability may … Sep 22, 2026
CVE-2026-65130 HIGH 8.0 NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to … Sep 22, 2026
CVE-2026-65129 MEDIUM 6.7 NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to … Sep 22, 2026
CVE-2026-65128 HIGH 8.8 NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code … Sep 22, 2026
CVE-2026-65127 MEDIUM 4.1 NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause exposure of sensitive system information due to uncleared debug information. A successful … Sep 22, 2026
CVE-2026-65126 MEDIUM 5.0 NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workflow. A successful exploit of this vulnerability … Sep 22, 2026
CVE-2026-65125 MEDIUM 6.6 NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path. A successful exploit of … Sep 22, 2026
CVE-2026-65124 MEDIUM 5.9 NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of this vulnerability might lead to … Sep 22, 2026