Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55639
Total
4397
Critical
16518
High
16189
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-76805 | MEDIUM | 5.3 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path in pkg/fuzz/parts.go can evaluate substituted runtime … | Sep 22, 2026 |
| CVE-2026-76804 | MEDIUM | 5.5 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loading path does not enforce the -file … | Sep 22, 2026 |
| CVE-2026-76803 | MEDIUM | 5.3 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript library does not enforce the local-file sandbox … | Sep 22, 2026 |
| CVE-2026-76802 | MEDIUM | 4.7 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply the unsigned … | Sep 22, 2026 |
| CVE-2026-56682 | MEDIUM | 5.3 | 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper use … | Sep 22, 2026 |
| CVE-2026-13087 | HIGH | 8.8 | A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c. When a crafted RPC-over-RDMA client sends a large … | Sep 22, 2026 |
| CVE-2026-95806 | UNKNOWN | — | MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point. The phar stream wrapper causes PHP … | Sep 22, 2026 |
| CVE-2026-95805 | UNKNOWN | — | A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action to reference the permission string 'theming_enabled*' (with a … | Sep 22, 2026 |
| CVE-2026-95655 | HIGH | 8.1 | Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages. Attackers can submit … | Sep 22, 2026 |
| CVE-2026-95654 | HIGH | 7.4 | Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization decision without re-checking token validity during acceptance. Attackers with a … | Sep 22, 2026 |
| CVE-2026-95653 | HIGH | 7.5 | Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable. Unauthenticated attackers can … | Sep 22, 2026 |
| CVE-2026-94640 | HIGH | 7.5 | A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number … | Sep 22, 2026 |
| CVE-2026-92706 | LOW | 3.4 | Dark Reader is an accessibility browser extension that makes web pages colors dark. Prior to 4.9.126, a website can cause the browser extension's image inversion … | Sep 22, 2026 |
| CVE-2026-90462 | MEDIUM | 5.4 | A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP … | Sep 22, 2026 |
| CVE-2026-88010 | UNKNOWN | — | Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.7.13, checkPassword in pkg/middlewares/auth/basic_auth.go constructs the BasicAuth singleflight key from the … | Sep 22, 2026 |
| CVE-2026-86805 | MEDIUM | 6.3 | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local … | Sep 22, 2026 |
| CVE-2026-86698 | UNKNOWN | — | Insufficient Session Expiration vulnerability in OAuth token issuance in hexpm hexpm allows a user whose organization membership or session has ended to keep reading the … | Sep 22, 2026 |
| CVE-2026-85055 | UNKNOWN | — | Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.22.0, field-level read permission is enforced on selected output fields but not on GraphQL … | Sep 22, 2026 |
| CVE-2026-81886 | MEDIUM | 5.5 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit crash-dump dmp64 parser was vulnerable because the Windows dmp64 … | Sep 22, 2026 |
| CVE-2026-81885 | MEDIUM | 5.5 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's NE relocation fixup-chain parser was vulnerable because the NE relocation parser … | Sep 22, 2026 |
| CVE-2026-81884 | LOW | 2.5 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O LC_DATA_IN_CODE parser was vulnerable because the Mach-O LC_DATA_IN_CODE parser trusted … | Sep 22, 2026 |
| CVE-2026-81883 | LOW | 3.3 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Lua 5.3 bytecode function parser was vulnerable because the Lua 5.3 … | Sep 22, 2026 |
| CVE-2026-81882 | LOW | 3.3 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's binary property-list Unicode parser was vulnerable because the binary-property-list Unicode parser … | Sep 22, 2026 |
| CVE-2026-81881 | LOW | 3.3 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field … | Sep 22, 2026 |
| CVE-2026-81880 | MEDIUM | 5.5 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Apple Preferred Executable Format loader was vulnerable because the PEF loader … | Sep 22, 2026 |