Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

55639
Total
4397
Critical
16518
High
16189
Medium
CVE ID Severity Score Description Published
CVE-2026-18460 UNKNOWN — Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 … Sep 22, 2026
CVE-2026-18459 UNKNOWN — Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before … Sep 22, 2026
CVE-2026-18458 UNKNOWN — Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows … Sep 22, 2026
CVE-2026-18457 UNKNOWN — Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before … Sep 22, 2026
CVE-2026-11389 UNKNOWN — Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows … Sep 22, 2026
CVE-2026-11388 UNKNOWN — Double Free vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.1.0 before 7.3.1.6. Sep 22, 2026
CVE-2026-95818 LOW 3.6 A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash … Sep 22, 2026
CVE-2026-94456 CRITICAL 9.1 Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source. The same helper is used for OAuth access tokens, authorization codes, client secrets, … Sep 22, 2026
CVE-2026-94455 HIGH 7.1 An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session. The authentication middleware is bound only to an explicit list … Sep 22, 2026
CVE-2026-87902 HIGH 8.1 An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both … Sep 22, 2026
CVE-2026-86062 MEDIUM 6.1 LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieval/ChatMessage.tsx renders answer and thinking content with react-markdown, rehypeRaw, and skipHtml=false without an HTML sanitizer. … Sep 22, 2026
CVE-2026-86059 CRITICAL 9.6 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organization members without Git provider access can retrieve plaintext provider credentials … Sep 22, 2026
CVE-2026-85740 HIGH 7.1 LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parser/markdown/parser.py evaluates the literal resolved address with ipaddress.is_global without consistently classifying an IPv4 … Sep 22, 2026
CVE-2026-85734 CRITICAL 9.1 LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.py does not impose a rate limit, account lockout, delay, … Sep 22, 2026
CVE-2026-85725 MEDIUM 5.9 LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwords.py compares plaintext AUTH_ACCOUNTS password values with Python's == operator. The comparison can … Sep 22, 2026
CVE-2026-85709 MEDIUM 5.3 LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, … Sep 22, 2026
CVE-2026-84301 MEDIUM 6.3 FastGPT is an open-source LLM platform for building AI applications on a knowledge base. Prior to 4.15.2, the safe Axios request interceptor in packages/service/common/api/axios.ts validates … Sep 22, 2026
CVE-2026-83803 UNKNOWN — Sentry is an error tracking and performance monitoring tool. From 23.11.0 until 26.7.0, Sentry instances with the relocation feature enabled unsafely deserialize a legacy database … Sep 22, 2026
CVE-2026-83603 HIGH 8.4 Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-status-socket in src/collectors/utils/ndsudo.c accepts a caller-controlled --socket_path from the low-privileged … Sep 22, 2026
CVE-2026-83602 MEDIUM 6.5 Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in src/web/api/v3/web_api_v3.c with HTTP_ACL_NOCHECK and HTTP_ACCESS_ANONYMOUS_DATA, causing unauthenticated PUT requests handled … Sep 22, 2026
CVE-2026-83601 MEDIUM 6.5 Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized DIMENSION SLOT value that str2ull_encoded passes to … Sep 22, 2026
CVE-2026-83600 MEDIUM 6.5 Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized CHART SLOT value that str2ull_encoded passes to … Sep 22, 2026
CVE-2026-83599 HIGH 7.5 Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates permessage-deflate before authentication, and src/web/websocket/websocket-compression.c allows websocket_client_decompress_message() to grow decompressed … Sep 22, 2026
CVE-2026-83598 HIGH 7.8 Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and … Sep 22, 2026
CVE-2026-76819 UNKNOWN — Rejected reason: Further research determined the issue results from a dependency. Sep 22, 2026