Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55639
Total
4397
Critical
16518
High
16189
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-59814 | HIGH | 7.6 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's GET /shares/:id?resource_id= route serves … | Sep 21, 2026 |
| CVE-2026-55210 | HIGH | 7.4 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's UserModel.ssoLogin() returns an existing … | Sep 21, 2026 |
| CVE-2026-46650 | MEDIUM | 4.4 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, isAcceptedUrl() in packages/renderer/htmlUtils.ts uses an unanchored … | Sep 21, 2026 |
| CVE-2026-17054 | MEDIUM | 5.3 | The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-processor in esp_hosted_event_task(). For control frames it took the 16-bit TLV … | Sep 21, 2026 |
| CVE-2026-15890 | MEDIUM | 5.3 | The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead_get_nonce() in subsys/secure_storage/src/its/transform/aead_get.c, stores its nonce counter in unsynchronized function-local static variables … | Sep 21, 2026 |
| CVE-2026-94588 | MEDIUM | 4.4 | In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is caused by improper handling of user-supplied input passed to … | Sep 21, 2026 |
| CVE-2026-94572 | UNKNOWN | — | In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written … | Sep 21, 2026 |
| CVE-2026-94571 | UNKNOWN | — | In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 … | Sep 21, 2026 |
| CVE-2026-94424 | HIGH | 8.8 | A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of … | Sep 21, 2026 |
| CVE-2026-93433 | MEDIUM | 5.5 | A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specially crafted SCSI (Small Computer System … | Sep 21, 2026 |
| CVE-2026-88746 | HIGH | 7.1 | idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/makeDiy_deal.php. | Sep 21, 2026 |
| CVE-2026-88745 | MEDIUM | 6.1 | EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell. | Sep 21, 2026 |
| CVE-2026-88467 | UNKNOWN | — | CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification function that returns the wrong type of value, causing errors and leaking sensitive information. | Sep 21, 2026 |
| CVE-2026-88412 | MEDIUM | 5.3 | An integer overflow in the _BulkInsert_ReadProperty component (/bulk_insert.c) of FalkorDB (Redis module) v4.20.1 allows attackers to cause a Denial of Service (DoS) via a crafted … | Sep 21, 2026 |
| CVE-2026-88411 | HIGH | 7.5 | Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4.20.1 leads to a Denial of Service (DoS) within the application. | Sep 21, 2026 |
| CVE-2026-88410 | HIGH | 7.1 | The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered as a write command, leading to unexpected behavior within the application. | Sep 21, 2026 |
| CVE-2026-88409 | HIGH | 8.8 | FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix function (/v19/decode_matrix.c). This vulnerability allows attackers to cause a … | Sep 21, 2026 |
| CVE-2026-88408 | MEDIUM | 6.5 | FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _GetGroup() function (/ops/op_aggregate.c). This vulnerability allows attackers to cause a … | Sep 21, 2026 |
| CVE-2026-88407 | HIGH | 7.5 | An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20.4 allows attackers to cause a Denial of Service (DoS) via a … | Sep 21, 2026 |
| CVE-2026-88406 | HIGH | 7.5 | FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _ValidateUnion_Clauses function (/ast/ast_validations.c). This vulnerability allows attackers to cause a … | Sep 21, 2026 |
| CVE-2026-88405 | UNKNOWN | — | A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionService function (/remote/remote-register-function.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload. | Sep 21, 2026 |
| CVE-2026-88404 | CRITICAL | 9.8 | A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload. | Sep 21, 2026 |
| CVE-2026-88403 | MEDIUM | 6.5 | A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request. | Sep 21, 2026 |
| CVE-2026-88402 | CRITICAL | 9.8 | A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements. | Sep 21, 2026 |
| CVE-2026-79919 | MEDIUM | 6.3 | MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, function-library code running under the LD_PRELOAD sandbox can invoke ctypes.CDLL from an importlib.abc.MetaPathFinder … | Sep 21, 2026 |