Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55639
Total
4397
Critical
16518
High
16189
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-75517 | MEDIUM | 6.5 | Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu integration mutation use cases including remove-integration, update-integration, auto-configure-integration, and set-integration-as-primary look … | Sep 22, 2026 |
| CVE-2026-75511 | UNKNOWN | — | Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu accepts chat webhook URLs from subscriber credentials.webhookUrl, channel endpoint endpoint.url, event … | Sep 22, 2026 |
| CVE-2026-75510 | UNKNOWN | — | Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu's @novu/js In-App Inbox and the @novu/react Inbox component accept a notification … | Sep 22, 2026 |
| CVE-2026-70410 | HIGH | 8.8 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite Avatica. Plugin instantiation (via AvaticaUtils#instantiatePlugin and other methods) initializes arbitrary … | Sep 22, 2026 |
| CVE-2026-63374 | UNKNOWN | — | AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() … | Sep 22, 2026 |
| CVE-2026-56681 | HIGH | 7.3 | 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper trust … | Sep 22, 2026 |
| CVE-2026-95754 | UNKNOWN | — | In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification branch did not include the User.disabled column in its … | Sep 22, 2026 |
| CVE-2026-95703 | UNKNOWN | — | In MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with filesystem probes (file_exists, MIME type detection, EXIF reading) before verifying that the value corresponded … | Sep 22, 2026 |
| CVE-2026-95701 | UNKNOWN | — | In MISP, the __statisticsOrgs method in UsersController.php used the organization name directly as a file-system path component when checking for the existence of an organization … | Sep 22, 2026 |
| CVE-2026-95698 | UNKNOWN | — | The findOrgImage method in MISP's OrgImgHelper constructs a filesystem path by concatenating a user-supplied organization identifier with a fixed image directory and a file extension, … | Sep 22, 2026 |
| CVE-2026-95697 | UNKNOWN | — | MISP contains an authorization flaw in the Organisation model's captureOrg method. When the $force parameter is set to true, the method unconditionally overwrites organization metadata … | Sep 22, 2026 |
| CVE-2026-95693 | UNKNOWN | — | In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), mime_content_type(), and exif_imagetype() on the supplied path before verifying that the … | Sep 22, 2026 |
| CVE-2026-95685 | UNKNOWN | — | MISP contains an access control flaw in the EventReports functionality. The replaceSuggestionInReport action, which allows modification of suggestion content within an event report, was incorrectly … | Sep 22, 2026 |
| CVE-2026-95683 | UNKNOWN | — | In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes. The enrichment logic fetched the report using … | Sep 22, 2026 |
| CVE-2026-95501 | MEDIUM | 4.3 | A vulnerability was found in mtrano APENCMS up to 6546096d354153309693efabb9a0d824628ed4f5. The affected element is the function eval of the file cms/weasel.php of the component Template … | Sep 22, 2026 |
| CVE-2026-95500 | HIGH | 7.3 | A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.php of the component Save Handler. … | Sep 22, 2026 |
| CVE-2026-94570 | MEDIUM | 5.9 | SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decode worker, which enables an unauthenticated remote attacker … | Sep 22, 2026 |
| CVE-2026-94127 | CRITICAL | 9.8 | When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution … | Sep 22, 2026 |
| CVE-2026-93344 | MEDIUM | 6.5 | MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_get_page_content AJAX action that allows authenticated attackers with subscriber-level access or higher … | Sep 22, 2026 |
| CVE-2026-93088 | CRITICAL | 9.8 | SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network … | Sep 22, 2026 |
| CVE-2026-89407 | HIGH | 7.5 | NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT, added in 2.17.2. PATTERN_FLOAT places adjacent quantifiers … | Sep 22, 2026 |
| CVE-2026-84388 | CRITICAL | 9.6 | A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may … | Sep 22, 2026 |
| CVE-2026-79315 | MEDIUM | 4.7 | A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The management interface reflects the raw request URI into a client-side template binding expression used for … | Sep 22, 2026 |
| CVE-2026-79314 | UNKNOWN | — | A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, protocol, … | Sep 22, 2026 |
| CVE-2026-79313 | CRITICAL | 9.8 | webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead of checking the last-access … | Sep 22, 2026 |