Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55714
Total
4403
Critical
16544
High
16275
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-49811 | HIGH | 8.4 | Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access … | Sep 21, 2026 |
| CVE-2026-48521 | MEDIUM | 5.9 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ProdClusterManagerFactory::allocateConnPool dereferences transport_socket_options while … | Sep 21, 2026 |
| CVE-2026-45381 | UNKNOWN | — | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search endpoint inserts its user-controlled query parameter into … | Sep 21, 2026 |
| CVE-2026-94501 | HIGH | 8.8 | jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without … | Sep 21, 2026 |
| CVE-2026-94497 | HIGH | 8.3 | jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and … | Sep 21, 2026 |
| CVE-2026-94496 | HIGH | 8.3 | jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify any role's data scope or delete roles. Attackers … | Sep 21, 2026 |
| CVE-2026-94495 | HIGH | 7.1 | jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticated users to modify tenant system configuration. Attackers can rewrite or delete tenant-wide … | Sep 21, 2026 |
| CVE-2026-94494 | MEDIUM | 5.0 | jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info endpoint. Attackers can … | Sep 21, 2026 |
| CVE-2026-94414 | MEDIUM | 5.4 | jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticated users to modify role button-permission definitions. Attackers can supply … | Sep 21, 2026 |
| CVE-2026-94413 | MEDIUM | 6.5 | jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve unsalted MD5 password digests for any user. Attackers … | Sep 21, 2026 |
| CVE-2026-94412 | HIGH | 8.8 | jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticated users to reset any other user's password. Attackers can … | Sep 21, 2026 |
| CVE-2026-94411 | HIGH | 8.8 | jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbitrary roles. Attackers can send a POST … | Sep 21, 2026 |
| CVE-2026-94403 | HIGH | 8.8 | A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library ene.sys of the component IOCTL Handler. This manipulation … | Sep 21, 2026 |
| CVE-2026-91167 | UNKNOWN | — | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.28.4, PUT /@warpgate/admin/api/users/:id/roles/:role_id reaches api_update_user_role in warpgate-admin/src/api/users.rs through AdminContext but … | Sep 21, 2026 |
| CVE-2026-91166 | MEDIUM | 5.7 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path in warpgate-web-ssh/src/manager.rs handles RCEvent::HostKeyUnknown … | Sep 21, 2026 |
| CVE-2026-91165 | LOW | 2.4 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.27.6, the response_mode=form_post SSO return path in warpgate-protocol-http/src/api/sso_provider_list.rs uses serde_json::to_string … | Sep 21, 2026 |
| CVE-2026-91164 | MEDIUM | 4.3 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API token authentication resolves ConfigProvider::validate_api_token into RequestAuthorization::UserToken … | Sep 21, 2026 |
| CVE-2026-82165 | MEDIUM | 5.5 | Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access … | Sep 21, 2026 |
| CVE-2026-82163 | MEDIUM | 5.5 | Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access … | Sep 21, 2026 |
| CVE-2026-66280 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 21, 2026 |
| CVE-2026-63330 | HIGH | 7.7 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_stream in warpgate-admin/src/api/recordings_detail.rs protects /@warpgate/admin/api/recordings/{uuid}/stream only with session authentication … | Sep 21, 2026 |
| CVE-2026-63329 | MEDIUM | 4.9 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request in warpgate-protocol-http/src/proxy.rs forwards a client-supplied x-warpgate-username header before … | Sep 21, 2026 |
| CVE-2026-61749 | MEDIUM | 6.5 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author report or label templates can cause WeasyPrint report … | Sep 21, 2026 |
| CVE-2026-61748 | MEDIUM | 4.3 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, ReportPrint at POST /api/report/print/ and LabelPrint at POST /api/report/label/print/ require authentication but do not … | Sep 21, 2026 |
| CVE-2026-61747 | MEDIUM | 4.3 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the /api/importer/row/ and /api/importer/mapping/ endpoints do not scope DataImportRow and DataImportColumnMap querysets to the … | Sep 21, 2026 |