Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55714
Total
4403
Critical
16544
High
16275
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-36472 | MEDIUM | 5.2 | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allows a remote attacker to execute arbitrary JavaScript in … | Sep 21, 2026 |
| CVE-2026-36471 | UNKNOWN | — | Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker to inject arbitrary values into internal request variables … | Sep 21, 2026 |
| CVE-2026-36470 | UNKNOWN | — | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied into the response HTML unmodified/unescaped during … | Sep 21, 2026 |
| CVE-2026-36469 | UNKNOWN | — | CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Media Manager's "Upload by URL" functionality). | Sep 21, 2026 |
| CVE-2026-36468 | MEDIUM | 6.1 | Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitrarily named URL parameter key, with part of its name … | Sep 21, 2026 |
| CVE-2026-36467 | HIGH | 7.2 | Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute … | Sep 21, 2026 |
| CVE-2026-94301 | CRITICAL | 9.8 | The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 … | Sep 21, 2026 |
| CVE-2026-94184 | HIGH | 8.1 | A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send … | Sep 21, 2026 |
| CVE-2026-93339 | MEDIUM | 5.4 | Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that allows authenticated users with Author-level privileges or higher to inject arbitrary HTML … | Sep 21, 2026 |
| CVE-2026-86473 | CRITICAL | 9.1 | Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential … | Sep 21, 2026 |
| CVE-2026-82355 | MEDIUM | 4.2 | When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the … | Sep 21, 2026 |
| CVE-2026-80110 | HIGH | 8.1 | A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string … | Sep 21, 2026 |
| CVE-2026-75939 | HIGH | 7.4 | A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire … | Sep 21, 2026 |
| CVE-2026-75158 | MEDIUM | 4.3 | Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized … | Sep 21, 2026 |
| CVE-2026-71543 | UNKNOWN | — | OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies could substitute attacker-controlled identity data without rejecting … | Sep 21, 2026 |
| CVE-2026-68919 | UNKNOWN | — | GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material modification comments that mimic the special … | Sep 21, 2026 |
| CVE-2026-61630 | MEDIUM | 4.2 | nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can … | Sep 21, 2026 |
| CVE-2026-61629 | HIGH | 7.5 | nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs … | Sep 21, 2026 |
| CVE-2026-61628 | HIGH | 8.1 | nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a … | Sep 21, 2026 |
| CVE-2026-55870 | UNKNOWN | — | GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators stored in the userinfo portion of source control material … | Sep 21, 2026 |
| CVE-2026-55625 | MEDIUM | 4.9 | GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/admin/internal/material_test and /go/api/internal/config_repos/*/material_test accept an arbitrary existing pipeline … | Sep 21, 2026 |
| CVE-2026-55567 | HIGH | 7.8 | BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's parent … | Sep 21, 2026 |
| CVE-2026-55074 | UNKNOWN | — | Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3.0, the jailexec connection plugin's put_file resolved a … | Sep 21, 2026 |
| CVE-2026-55071 | HIGH | 8.4 | MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0, the ado_package_install MCP tool in stata-mcp … | Sep 21, 2026 |
| CVE-2026-55060 | LOW | 3.7 | GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can … | Sep 21, 2026 |