Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55639
Total
4397
Critical
16518
High
16189
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-95656 | HIGH | 7.3 | A vulnerability was found in dgtlmoon changedetection.io up to 50389b07. This vulnerability affects the function add_watch_ui_snapshot of the file changedetectionio/blueprint/add_watch_ui/__init__.py of the component Preview Endpoint. … | Sep 22, 2026 |
| CVE-2026-95624 | MEDIUM | 6.8 | The Tauri updater plugin's 'check' IPC command accepts an allowDowngrades boolean parameter directly from frontend JavaScript code. When set to true, it replaces the version … | Sep 22, 2026 |
| CVE-2026-94384 | HIGH | 8.1 | Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26 allows any IAM principal with lambda:InvokeFunction permission on the affected function to escalate privileges and perform AWS API … | Sep 22, 2026 |
| CVE-2026-93345 | HIGH | 7.5 | MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker … | Sep 22, 2026 |
| CVE-2026-8849 | UNKNOWN | — | Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation. This issue affects Connext Professional: from 7.6.0 before 7.7.0.1. | Sep 22, 2026 |
| CVE-2026-89276 | CRITICAL | 9.9 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in … | Sep 22, 2026 |
| CVE-2026-89275 | CRITICAL | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in … | Sep 22, 2026 |
| CVE-2026-86056 | MEDIUM | 5.5 | Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the NPPM_SAVESESSION handler in PowerEditor/src/NppBigSwitch.cpp converts lParam to a sessionInfo pointer and dereferences … | Sep 22, 2026 |
| CVE-2026-86054 | HIGH | 7.8 | Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in NppParameters::writeSession in PowerEditor/src/Parameters.cpp because it copies … | Sep 22, 2026 |
| CVE-2026-85995 | HIGH | 7.3 | Notepad++ is a free and open-source source code editor. From 8.9.7 until 8.9.8, the Notepad++ updater and signature verification path can accept a modified GUP.exe … | Sep 22, 2026 |
| CVE-2026-85288 | MEDIUM | 6.7 | Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ incompletely enforces shortcuts.xml HMAC validation because WM_MACRODLGRUNMACRO, the Run a Macro Multiple … | Sep 22, 2026 |
| CVE-2026-85279 | HIGH | 8.6 | Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in PluginsManager::loadPluginFromPath in PowerEditor/src/MISC/PluginsManager/PluginsManager.cpp because the plugin-supplied … | Sep 22, 2026 |
| CVE-2026-84412 | CRITICAL | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in … | Sep 22, 2026 |
| CVE-2026-83660 | CRITICAL | 9.9 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not … | Sep 22, 2026 |
| CVE-2026-83597 | HIGH | 7.0 | Netdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent MSI repair launches powershell.exe and wevtutil.exe as elevated interactive processes … | Sep 22, 2026 |
| CVE-2026-82443 | CRITICAL | 9.6 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this … | Sep 22, 2026 |
| CVE-2026-82013 | CRITICAL | 9.9 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this … | Sep 22, 2026 |
| CVE-2026-82011 | CRITICAL | 9.1 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in … | Sep 22, 2026 |
| CVE-2026-82010 | CRITICAL | 9.9 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in … | Sep 22, 2026 |
| CVE-2026-82009 | CRITICAL | 9.1 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in … | Sep 22, 2026 |
| CVE-2026-82008 | CRITICAL | 9.9 | Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current … | Sep 22, 2026 |
| CVE-2026-82003 | HIGH | 8.5 | Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current … | Sep 22, 2026 |
| CVE-2026-7866 | UNKNOWN | — | Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before … | Sep 22, 2026 |
| CVE-2026-77605 | HIGH | 7.8 | Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the Folder as Workspace Run by system action in Notepad++ can resolve a … | Sep 22, 2026 |
| CVE-2026-77274 | UNKNOWN | — | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_url_for_ssrf has a backslash authority confusion because … | Sep 22, 2026 |