Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

55639
Total
4397
Critical
16518
High
16189
Medium
CVE ID Severity Score Description Published
CVE-2026-76805 MEDIUM 5.3 Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path in pkg/fuzz/parts.go can evaluate substituted runtime … Sep 22, 2026
CVE-2026-76804 MEDIUM 5.5 Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loading path does not enforce the -file … Sep 22, 2026
CVE-2026-76803 MEDIUM 5.3 Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript library does not enforce the local-file sandbox … Sep 22, 2026
CVE-2026-76802 MEDIUM 4.7 Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply the unsigned … Sep 22, 2026
CVE-2026-56682 MEDIUM 5.3 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper use … Sep 22, 2026
CVE-2026-13087 HIGH 8.8 A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c. When a crafted RPC-over-RDMA client sends a large … Sep 22, 2026
CVE-2026-95806 UNKNOWN — MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point. The phar stream wrapper causes PHP … Sep 22, 2026
CVE-2026-95805 UNKNOWN — A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action to reference the permission string 'theming_enabled*' (with a … Sep 22, 2026
CVE-2026-95655 HIGH 8.1 Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages. Attackers can submit … Sep 22, 2026
CVE-2026-95654 HIGH 7.4 Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization decision without re-checking token validity during acceptance. Attackers with a … Sep 22, 2026
CVE-2026-95653 HIGH 7.5 Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable. Unauthenticated attackers can … Sep 22, 2026
CVE-2026-94640 HIGH 7.5 A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number … Sep 22, 2026
CVE-2026-92706 LOW 3.4 Dark Reader is an accessibility browser extension that makes web pages colors dark. Prior to 4.9.126, a website can cause the browser extension's image inversion … Sep 22, 2026
CVE-2026-90462 MEDIUM 5.4 A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP … Sep 22, 2026
CVE-2026-88010 UNKNOWN — Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.7.13, checkPassword in pkg/middlewares/auth/basic_auth.go constructs the BasicAuth singleflight key from the … Sep 22, 2026
CVE-2026-86805 MEDIUM 6.3 A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local … Sep 22, 2026
CVE-2026-86698 UNKNOWN — Insufficient Session Expiration vulnerability in OAuth token issuance in hexpm hexpm allows a user whose organization membership or session has ended to keep reading the … Sep 22, 2026
CVE-2026-85055 UNKNOWN — Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.22.0, field-level read permission is enforced on selected output fields but not on GraphQL … Sep 22, 2026
CVE-2026-81886 MEDIUM 5.5 radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit crash-dump dmp64 parser was vulnerable because the Windows dmp64 … Sep 22, 2026
CVE-2026-81885 MEDIUM 5.5 radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's NE relocation fixup-chain parser was vulnerable because the NE relocation parser … Sep 22, 2026
CVE-2026-81884 LOW 2.5 radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O LC_DATA_IN_CODE parser was vulnerable because the Mach-O LC_DATA_IN_CODE parser trusted … Sep 22, 2026
CVE-2026-81883 LOW 3.3 radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Lua 5.3 bytecode function parser was vulnerable because the Lua 5.3 … Sep 22, 2026
CVE-2026-81882 LOW 3.3 radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's binary property-list Unicode parser was vulnerable because the binary-property-list Unicode parser … Sep 22, 2026
CVE-2026-81881 LOW 3.3 radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field … Sep 22, 2026
CVE-2026-81880 MEDIUM 5.5 radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Apple Preferred Executable Format loader was vulnerable because the PEF loader … Sep 22, 2026