Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-73637 | HIGH | 7.3 | Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication … | Oct 01, 2026 |
| CVE-2026-73636 | HIGH | 8.1 | Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured … | Oct 01, 2026 |
| CVE-2026-67172 | LOW | 3.7 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in error messages when invalid inputs are sent to … | Oct 01, 2026 |
| CVE-2026-67171 | MEDIUM | 5.3 | HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint exposes sensitive internal database information. This information could enable … | Oct 01, 2026 |
| CVE-2026-63718 | HIGH | 7.5 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This … | Oct 01, 2026 |
| CVE-2026-63686 | HIGH | 7.5 | A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause … | Oct 01, 2026 |
| CVE-2026-63292 | HIGH | 7.5 | Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial … | Oct 01, 2026 |
| CVE-2026-63045 | HIGH | 7.5 | Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy … | Oct 01, 2026 |
| CVE-2026-59797 | CRITICAL | 9.8 | Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | Oct 01, 2026 |
| CVE-2026-59685 | HIGH | 7.5 | Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP … | Oct 01, 2026 |
| CVE-2026-58415 | MEDIUM | 5.3 | Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client … | Oct 01, 2026 |
| CVE-2026-57941 | CRITICAL | 9.8 | Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | Oct 01, 2026 |
| CVE-2026-56449 | HIGH | 7.5 | Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | Oct 01, 2026 |
| CVE-2026-56154 | CRITICAL | 9.8 | Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | Oct 01, 2026 |
| CVE-2026-56153 | HIGH | 7.5 | Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | Oct 01, 2026 |
| CVE-2026-48005 | HIGH | 7.5 | Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a … | Oct 01, 2026 |
| CVE-2026-21833 | LOW | 3.7 | HCL AION is affected by a vulnerability in which the Content-Security-Policy (CSP) HTTP response header is not configured. CSP helps prevent attacks such as Cross-Site … | Oct 01, 2026 |
| CVE-2026-14316 | HIGH | 8.1 | The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted … | Oct 01, 2026 |
| CVE-2026-13043 | UNKNOWN | — | A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the … | Oct 01, 2026 |
| CVE-2026-12544 | HIGH | 7.7 | A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct … | Oct 01, 2026 |
| CVE-2026-12541 | HIGH | 8.2 | A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied … | Oct 01, 2026 |
| CVE-2026-12540 | HIGH | 8.2 | A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system … | Oct 01, 2026 |
| CVE-2026-12423 | HIGH | 7.5 | A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw … | Oct 01, 2026 |
| CVE-2026-12405 | HIGH | 8.8 | A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations). When a job template has the effective_user … | Oct 01, 2026 |
| CVE-2026-103921 | HIGH | 7.4 | GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js … | Oct 01, 2026 |