Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55639
Total
4397
Critical
16518
High
16189
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-63275 | UNKNOWN | — | LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number … | Sep 22, 2026 |
| CVE-2026-63274 | UNKNOWN | — | LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the … | Sep 22, 2026 |
| CVE-2026-63273 | UNKNOWN | — | LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from … | Sep 22, 2026 |
| CVE-2026-63272 | UNKNOWN | — | LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own … | Sep 22, 2026 |
| CVE-2026-95623 | MEDIUM | 5.6 | The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial request. When the remote server responds with … | Sep 22, 2026 |
| CVE-2026-92882 | UNKNOWN | — | Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated … | Sep 22, 2026 |
| CVE-2026-90990 | UNKNOWN | — | Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional … | Sep 22, 2026 |
| CVE-2026-94117 | HIGH | 7.6 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection. This … | Sep 22, 2026 |
| CVE-2026-90882 | UNKNOWN | — | The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints. A page on any origin could therefore … | Sep 22, 2026 |
| CVE-2026-25265 | HIGH | 8.8 | Privilege escalation due to weak configuration while temporary file handling. | Sep 22, 2026 |
| CVE-2026-25264 | HIGH | 8.8 | Privilege escalation due to weak configuration during package extraction process. | Sep 22, 2026 |
| CVE-2026-25262 | MEDIUM | 6.9 | Memory corruption while processing a crafted ELF file in the Primary Bootloader. | Sep 22, 2026 |
| CVE-2026-25255 | HIGH | 8.8 | Exposed dangerous function lead to privilege escalation via gRPC server. | Sep 22, 2026 |
| CVE-2026-25254 | CRITICAL | 9.8 | Improper authorization leads to Remote Code Execution via SocketIO interface. | Sep 22, 2026 |
| CVE-2026-9231 | HIGH | 7.5 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up … | Sep 22, 2026 |
| CVE-2026-95511 | UNKNOWN | — | Rejected reason: Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in cupsd admin role granted … | Sep 22, 2026 |
| CVE-2026-95508 | HIGH | 7.4 | A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, … | Sep 22, 2026 |
| CVE-2026-93928 | HIGH | 7.3 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass. This issue affects Taxi Booking … | Sep 22, 2026 |
| CVE-2026-93556 | UNKNOWN | — | The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is … | Sep 22, 2026 |
| CVE-2026-89422 | UNKNOWN | — | Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A … | Sep 22, 2026 |
| CVE-2026-68956 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote attacker to exhaust node memory by repeatedly opening session channels … | Sep 22, 2026 |
| CVE-2026-65634 | UNKNOWN | — | Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause denial of service by sending a crafted OID … | Sep 22, 2026 |
| CVE-2026-15095 | MEDIUM | 4.9 | The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress is vulnerable to Directory Traversal in … | Sep 22, 2026 |
| CVE-2026-9004 | MEDIUM | 4.3 | The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.6 … | Sep 22, 2026 |
| CVE-2026-95503 | MEDIUM | 6.8 | A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos password authentication is used without … | Sep 22, 2026 |