Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55255
Total
4360
Critical
16420
High
16093
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-94533 | MEDIUM | 6.5 | lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated users to download arbitrary attachments. Attackers can retrieve other users' stored files … | Sep 21, 2026 |
| CVE-2026-94532 | MEDIUM | 6.5 | lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user's full profile. Attackers can … | Sep 21, 2026 |
| CVE-2026-93340 | MEDIUM | 6.8 | Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account … | Sep 21, 2026 |
| CVE-2026-88756 | UNKNOWN | — | Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array submitted to the public login endpoint (POST /user/authenticate). | Sep 21, 2026 |
| CVE-2026-88738 | HIGH | 8.8 | Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An authenticated attacker can upload a server-side … | Sep 21, 2026 |
| CVE-2026-79079 | HIGH | 7.8 | An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components | Sep 21, 2026 |
| CVE-2026-78847 | CRITICAL | 9.8 | An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to parse front matter when language is js/javascript.This … | Sep 21, 2026 |
| CVE-2026-78806 | UNKNOWN | — | An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in … | Sep 21, 2026 |
| CVE-2026-65980 | UNKNOWN | — | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.3, Chartbrew's … | Sep 21, 2026 |
| CVE-2026-61852 | UNKNOWN | — | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's … | Sep 21, 2026 |
| CVE-2026-61851 | UNKNOWN | — | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's … | Sep 21, 2026 |
| CVE-2026-61743 | MEDIUM | 6.3 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's … | Sep 21, 2026 |
| CVE-2026-61652 | UNKNOWN | — | Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion. The issue affects all callers who streamed … | Sep 21, 2026 |
| CVE-2026-61541 | UNKNOWN | — | Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests content from an untrusted server, or … | Sep 21, 2026 |
| CVE-2026-59830 | MEDIUM | 5.4 | Discourse is an open-source discussion platform. Prior to 2026.7.0, the post action component failed to escape user-controlled display names before interpolating them into an HTML … | Sep 21, 2026 |
| CVE-2026-59815 | MEDIUM | 4.3 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's ItemModel.checkIfAllowed() authorizes writes to … | Sep 21, 2026 |
| CVE-2026-59814 | HIGH | 7.6 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's GET /shares/:id?resource_id= route serves … | Sep 21, 2026 |
| CVE-2026-55210 | HIGH | 7.4 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's UserModel.ssoLogin() returns an existing … | Sep 21, 2026 |
| CVE-2026-46650 | MEDIUM | 4.4 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, isAcceptedUrl() in packages/renderer/htmlUtils.ts uses an unanchored … | Sep 21, 2026 |
| CVE-2026-17054 | MEDIUM | 5.3 | The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-processor in esp_hosted_event_task(). For control frames it took the 16-bit TLV … | Sep 21, 2026 |
| CVE-2026-15890 | MEDIUM | 5.3 | The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead_get_nonce() in subsys/secure_storage/src/its/transform/aead_get.c, stores its nonce counter in unsynchronized function-local static variables … | Sep 21, 2026 |
| CVE-2026-94588 | MEDIUM | 4.4 | In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is caused by improper handling of user-supplied input passed to … | Sep 21, 2026 |
| CVE-2026-94572 | UNKNOWN | — | In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written … | Sep 21, 2026 |
| CVE-2026-94571 | UNKNOWN | — | In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 … | Sep 21, 2026 |
| CVE-2026-94424 | HIGH | 8.8 | A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of … | Sep 21, 2026 |