Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55639
Total
4397
Critical
16518
High
16189
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-95667 | UNKNOWN | — | The MISP installer scripts (for Debian 12, Debian 13, Ubuntu 24.04, and RHEL 9.4) create a log file at /var/log/misp_install.log and a named pipe (FIFO) … | Sep 22, 2026 |
| CVE-2026-95666 | MEDIUM | 4.3 | Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to limit the length of the post ID array accepted … | Sep 22, 2026 |
| CVE-2026-95665 | UNKNOWN | — | MISP contains a reflected cross-site scripting (XSS) vulnerability in the event REST search export confirmation form. The view template app/View/Events/ajax/eventRestSearchExportConfirmationForm.ctp renders a URL-supplied event ID … | Sep 22, 2026 |
| CVE-2026-95499 | HIGH | 7.3 | A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of … | Sep 22, 2026 |
| CVE-2026-95396 | MEDIUM | 4.3 | A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of the file HospitalController.java of the component Public Search Handlers. … | Sep 22, 2026 |
| CVE-2026-93343 | MEDIUM | 6.5 | MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_admin_vendors_ajax AJAX action that allows authenticated attackers with subscriber-level access or higher … | Sep 22, 2026 |
| CVE-2026-93342 | MEDIUM | 5.4 | MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_duplicate_product AJAX action that allows authenticated attackers with subscriber-level access or higher … | Sep 22, 2026 |
| CVE-2026-93341 | MEDIUM | 4.3 | MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_send_refund AJAX action that allows authenticated attackers with subscriber-level access or higher … | Sep 22, 2026 |
| CVE-2026-12718 | CRITICAL | 9.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic Industry and Trade Inc. KarelIPS allows Blind SQL Injection. … | Sep 22, 2026 |
| CVE-2026-95661 | UNKNOWN | — | MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes variable, which is derived from the URL path segment , … | Sep 22, 2026 |
| CVE-2026-95659 | UNKNOWN | — | MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject action. The method accepted a parent object type parameter from the URL without validation … | Sep 22, 2026 |
| CVE-2026-95658 | UNKNOWN | — | MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list. In CakePHP, listing an action in unlockedActions disables both the CSRF token check … | Sep 22, 2026 |
| CVE-2026-95619 | HIGH | 7.7 | A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This … | Sep 22, 2026 |
| CVE-2026-95273 | MEDIUM | 4.3 | A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of the file changedetectionio/flask_app.py of the component visual_selector_data. Executing a … | Sep 22, 2026 |
| CVE-2026-95272 | LOW | 3.7 | A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. This affects the function static_content of the file changedetectionio/flask_app.py of the component Screenshot Handler. Performing … | Sep 22, 2026 |
| CVE-2026-95271 | HIGH | 7.3 | A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_authentication of the file changedetectionio/flask_app.py of the component … | Sep 22, 2026 |
| CVE-2026-93616 | CRITICAL | 9.8 | A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server. | Sep 22, 2026 |
| CVE-2026-75791 | HIGH | 8.6 | Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API. | Sep 22, 2026 |
| CVE-2026-95270 | LOW | 3.7 | A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the function check_password of the file changedetectionio/flask_app.py of the component … | Sep 22, 2026 |
| CVE-2026-89420 | UNKNOWN | — | Improper Validation of Specified Quantity in Input in ZenHive mpp allows a client holding an open payment channel to obtain paid resources without being charged. … | Sep 22, 2026 |
| CVE-2026-87119 | UNKNOWN | — | Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly. The payer signs a … | Sep 22, 2026 |
| CVE-2026-74849 | CRITICAL | 9.8 | Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client. | Sep 22, 2026 |
| CVE-2026-63279 | UNKNOWN | — | LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour … | Sep 22, 2026 |
| CVE-2026-63278 | UNKNOWN | — | URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening … | Sep 22, 2026 |
| CVE-2026-63276 | UNKNOWN | — | LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may … | Sep 22, 2026 |