Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55639
Total
4397
Critical
16518
High
16189
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-18460 | UNKNOWN | — | Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 … | Sep 22, 2026 |
| CVE-2026-18459 | UNKNOWN | — | Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before … | Sep 22, 2026 |
| CVE-2026-18458 | UNKNOWN | — | Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows … | Sep 22, 2026 |
| CVE-2026-18457 | UNKNOWN | — | Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before … | Sep 22, 2026 |
| CVE-2026-11389 | UNKNOWN | — | Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows … | Sep 22, 2026 |
| CVE-2026-11388 | UNKNOWN | — | Double Free vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.1.0 before 7.3.1.6. | Sep 22, 2026 |
| CVE-2026-95818 | LOW | 3.6 | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash … | Sep 22, 2026 |
| CVE-2026-94456 | CRITICAL | 9.1 | Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source. The same helper is used for OAuth access tokens, authorization codes, client secrets, … | Sep 22, 2026 |
| CVE-2026-94455 | HIGH | 7.1 | An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session. The authentication middleware is bound only to an explicit list … | Sep 22, 2026 |
| CVE-2026-87902 | HIGH | 8.1 | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both … | Sep 22, 2026 |
| CVE-2026-86062 | MEDIUM | 6.1 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieval/ChatMessage.tsx renders answer and thinking content with react-markdown, rehypeRaw, and skipHtml=false without an HTML sanitizer. … | Sep 22, 2026 |
| CVE-2026-86059 | CRITICAL | 9.6 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organization members without Git provider access can retrieve plaintext provider credentials … | Sep 22, 2026 |
| CVE-2026-85740 | HIGH | 7.1 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parser/markdown/parser.py evaluates the literal resolved address with ipaddress.is_global without consistently classifying an IPv4 … | Sep 22, 2026 |
| CVE-2026-85734 | CRITICAL | 9.1 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.py does not impose a rate limit, account lockout, delay, … | Sep 22, 2026 |
| CVE-2026-85725 | MEDIUM | 5.9 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwords.py compares plaintext AUTH_ACCOUNTS password values with Python's == operator. The comparison can … | Sep 22, 2026 |
| CVE-2026-85709 | MEDIUM | 5.3 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, … | Sep 22, 2026 |
| CVE-2026-84301 | MEDIUM | 6.3 | FastGPT is an open-source LLM platform for building AI applications on a knowledge base. Prior to 4.15.2, the safe Axios request interceptor in packages/service/common/api/axios.ts validates … | Sep 22, 2026 |
| CVE-2026-83803 | UNKNOWN | — | Sentry is an error tracking and performance monitoring tool. From 23.11.0 until 26.7.0, Sentry instances with the relocation feature enabled unsafely deserialize a legacy database … | Sep 22, 2026 |
| CVE-2026-83603 | HIGH | 8.4 | Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-status-socket in src/collectors/utils/ndsudo.c accepts a caller-controlled --socket_path from the low-privileged … | Sep 22, 2026 |
| CVE-2026-83602 | MEDIUM | 6.5 | Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in src/web/api/v3/web_api_v3.c with HTTP_ACL_NOCHECK and HTTP_ACCESS_ANONYMOUS_DATA, causing unauthenticated PUT requests handled … | Sep 22, 2026 |
| CVE-2026-83601 | MEDIUM | 6.5 | Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized DIMENSION SLOT value that str2ull_encoded passes to … | Sep 22, 2026 |
| CVE-2026-83600 | MEDIUM | 6.5 | Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized CHART SLOT value that str2ull_encoded passes to … | Sep 22, 2026 |
| CVE-2026-83599 | HIGH | 7.5 | Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates permessage-deflate before authentication, and src/web/websocket/websocket-compression.c allows websocket_client_decompress_message() to grow decompressed … | Sep 22, 2026 |
| CVE-2026-83598 | HIGH | 7.8 | Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and … | Sep 22, 2026 |
| CVE-2026-76819 | UNKNOWN | — | Rejected reason: Further research determined the issue results from a dependency. | Sep 22, 2026 |