Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

55714
Total
4403
Critical
16544
High
16275
Medium
CVE ID Severity Score Description Published
CVE-2026-49811 HIGH 8.4 Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access … Sep 21, 2026
CVE-2026-48521 MEDIUM 5.9 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ProdClusterManagerFactory::allocateConnPool dereferences transport_socket_options while … Sep 21, 2026
CVE-2026-45381 UNKNOWN — Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search endpoint inserts its user-controlled query parameter into … Sep 21, 2026
CVE-2026-94501 HIGH 8.8 jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without … Sep 21, 2026
CVE-2026-94497 HIGH 8.3 jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and … Sep 21, 2026
CVE-2026-94496 HIGH 8.3 jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify any role's data scope or delete roles. Attackers … Sep 21, 2026
CVE-2026-94495 HIGH 7.1 jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticated users to modify tenant system configuration. Attackers can rewrite or delete tenant-wide … Sep 21, 2026
CVE-2026-94494 MEDIUM 5.0 jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info endpoint. Attackers can … Sep 21, 2026
CVE-2026-94414 MEDIUM 5.4 jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticated users to modify role button-permission definitions. Attackers can supply … Sep 21, 2026
CVE-2026-94413 MEDIUM 6.5 jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve unsalted MD5 password digests for any user. Attackers … Sep 21, 2026
CVE-2026-94412 HIGH 8.8 jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticated users to reset any other user's password. Attackers can … Sep 21, 2026
CVE-2026-94411 HIGH 8.8 jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbitrary roles. Attackers can send a POST … Sep 21, 2026
CVE-2026-94403 HIGH 8.8 A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library ene.sys of the component IOCTL Handler. This manipulation … Sep 21, 2026
CVE-2026-91167 UNKNOWN — Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.28.4, PUT /@warpgate/admin/api/users/:id/roles/:role_id reaches api_update_user_role in warpgate-admin/src/api/users.rs through AdminContext but … Sep 21, 2026
CVE-2026-91166 MEDIUM 5.7 Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path in warpgate-web-ssh/src/manager.rs handles RCEvent::HostKeyUnknown … Sep 21, 2026
CVE-2026-91165 LOW 2.4 Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.27.6, the response_mode=form_post SSO return path in warpgate-protocol-http/src/api/sso_provider_list.rs uses serde_json::to_string … Sep 21, 2026
CVE-2026-91164 MEDIUM 4.3 Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API token authentication resolves ConfigProvider::validate_api_token into RequestAuthorization::UserToken … Sep 21, 2026
CVE-2026-82165 MEDIUM 5.5 Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access … Sep 21, 2026
CVE-2026-82163 MEDIUM 5.5 Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access … Sep 21, 2026
CVE-2026-66280 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Sep 21, 2026
CVE-2026-63330 HIGH 7.7 Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_stream in warpgate-admin/src/api/recordings_detail.rs protects /@warpgate/admin/api/recordings/{uuid}/stream only with session authentication … Sep 21, 2026
CVE-2026-63329 MEDIUM 4.9 Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request in warpgate-protocol-http/src/proxy.rs forwards a client-supplied x-warpgate-username header before … Sep 21, 2026
CVE-2026-61749 MEDIUM 6.5 InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author report or label templates can cause WeasyPrint report … Sep 21, 2026
CVE-2026-61748 MEDIUM 4.3 InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, ReportPrint at POST /api/report/print/ and LabelPrint at POST /api/report/label/print/ require authentication but do not … Sep 21, 2026
CVE-2026-61747 MEDIUM 4.3 InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the /api/importer/row/ and /api/importer/mapping/ endpoints do not scope DataImportRow and DataImportColumnMap querysets to the … Sep 21, 2026