Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

55255
Total
4360
Critical
16420
High
16093
Medium
CVE ID Severity Score Description Published
CVE-2026-95661 UNKNOWN — MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes variable, which is derived from the URL path segment , … Sep 22, 2026
CVE-2026-95659 UNKNOWN — MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject action. The method accepted a parent object type parameter from the URL without validation … Sep 22, 2026
CVE-2026-95658 UNKNOWN — MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list. In CakePHP, listing an action in unlockedActions disables both the CSRF token check … Sep 22, 2026
CVE-2026-95619 HIGH 7.7 A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This … Sep 22, 2026
CVE-2026-95273 MEDIUM 4.3 A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of the file changedetectionio/flask_app.py of the component visual_selector_data. Executing a … Sep 22, 2026
CVE-2026-95272 LOW 3.7 A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. This affects the function static_content of the file changedetectionio/flask_app.py of the component Screenshot Handler. Performing … Sep 22, 2026
CVE-2026-95271 HIGH 7.3 A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_authentication of the file changedetectionio/flask_app.py of the component … Sep 22, 2026
CVE-2026-93616 CRITICAL 9.8 A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server. Sep 22, 2026
CVE-2026-75791 HIGH 8.6 Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API. Sep 22, 2026
CVE-2026-95270 LOW 3.7 A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the function check_password of the file changedetectionio/flask_app.py of the component … Sep 22, 2026
CVE-2026-89420 UNKNOWN — Improper Validation of Specified Quantity in Input in ZenHive mpp allows a client holding an open payment channel to obtain paid resources without being charged. … Sep 22, 2026
CVE-2026-87119 UNKNOWN — Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly. The payer signs a … Sep 22, 2026
CVE-2026-74849 CRITICAL 9.8 Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client. Sep 22, 2026
CVE-2026-63279 UNKNOWN — LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour … Sep 22, 2026
CVE-2026-63278 UNKNOWN — URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening … Sep 22, 2026
CVE-2026-63276 UNKNOWN — LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may … Sep 22, 2026
CVE-2026-63275 UNKNOWN — LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number … Sep 22, 2026
CVE-2026-63274 UNKNOWN — LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the … Sep 22, 2026
CVE-2026-63273 UNKNOWN — LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from … Sep 22, 2026
CVE-2026-63272 UNKNOWN — LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own … Sep 22, 2026
CVE-2026-95623 MEDIUM 5.6 The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial request. When the remote server responds with … Sep 22, 2026
CVE-2026-92882 UNKNOWN — Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated … Sep 22, 2026
CVE-2026-90990 UNKNOWN — Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional … Sep 22, 2026
CVE-2026-94117 HIGH 7.6 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection. This … Sep 22, 2026
CVE-2026-90882 UNKNOWN — The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints. A page on any origin could therefore … Sep 22, 2026