Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

55639
Total
4397
Critical
16518
High
16189
Medium
CVE ID Severity Score Description Published
CVE-2026-63275 UNKNOWN — LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number … Sep 22, 2026
CVE-2026-63274 UNKNOWN — LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the … Sep 22, 2026
CVE-2026-63273 UNKNOWN — LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from … Sep 22, 2026
CVE-2026-63272 UNKNOWN — LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own … Sep 22, 2026
CVE-2026-95623 MEDIUM 5.6 The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial request. When the remote server responds with … Sep 22, 2026
CVE-2026-92882 UNKNOWN — Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated … Sep 22, 2026
CVE-2026-90990 UNKNOWN — Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional … Sep 22, 2026
CVE-2026-94117 HIGH 7.6 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection. This … Sep 22, 2026
CVE-2026-90882 UNKNOWN — The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints. A page on any origin could therefore … Sep 22, 2026
CVE-2026-25265 HIGH 8.8 Privilege escalation due to weak configuration while temporary file handling. Sep 22, 2026
CVE-2026-25264 HIGH 8.8 Privilege escalation due to weak configuration during package extraction process. Sep 22, 2026
CVE-2026-25262 MEDIUM 6.9 Memory corruption while processing a crafted ELF file in the Primary Bootloader. Sep 22, 2026
CVE-2026-25255 HIGH 8.8 Exposed dangerous function lead to privilege escalation via gRPC server. Sep 22, 2026
CVE-2026-25254 CRITICAL 9.8 Improper authorization leads to Remote Code Execution via SocketIO interface. Sep 22, 2026
CVE-2026-9231 HIGH 7.5 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up … Sep 22, 2026
CVE-2026-95511 UNKNOWN — Rejected reason: Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in cupsd admin role granted … Sep 22, 2026
CVE-2026-95508 HIGH 7.4 A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, … Sep 22, 2026
CVE-2026-93928 HIGH 7.3 Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass. This issue affects Taxi Booking … Sep 22, 2026
CVE-2026-93556 UNKNOWN — The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is … Sep 22, 2026
CVE-2026-89422 UNKNOWN — Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A … Sep 22, 2026
CVE-2026-68956 UNKNOWN — Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote attacker to exhaust node memory by repeatedly opening session channels … Sep 22, 2026
CVE-2026-65634 UNKNOWN — Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause denial of service by sending a crafted OID … Sep 22, 2026
CVE-2026-15095 MEDIUM 4.9 The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress is vulnerable to Directory Traversal in … Sep 22, 2026
CVE-2026-9004 MEDIUM 4.3 The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.6 … Sep 22, 2026
CVE-2026-95503 MEDIUM 6.8 A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos password authentication is used without … Sep 22, 2026