Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

55714
Total
4403
Critical
16544
High
16275
Medium
CVE ID Severity Score Description Published
CVE-2026-54584 UNKNOWN — mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An … Sep 21, 2026
CVE-2026-52743 MEDIUM 4.3 GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs … Sep 21, 2026
CVE-2026-52742 UNKNOWN — GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server configuration to pipeline group administrators instead of … Sep 21, 2026
CVE-2026-52741 UNKNOWN — GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from commit comments when a project uses a lenient … Sep 21, 2026
CVE-2026-52740 UNKNOWN — GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names case-sensitively when selecting authorization filters. A … Sep 21, 2026
CVE-2026-94404 UNKNOWN — MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser without that user knowingly approving the change. … Sep 21, 2026
CVE-2026-94401 UNKNOWN — MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML … Sep 21, 2026
CVE-2026-94394 UNKNOWN — When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not … Sep 21, 2026
CVE-2026-94393 UNKNOWN — When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that … Sep 21, 2026
CVE-2026-94387 MEDIUM 5.4 Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping. … Sep 21, 2026
CVE-2026-94382 MEDIUM 4.2 Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or … Sep 21, 2026
CVE-2026-93884 UNKNOWN — Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this … Sep 21, 2026
CVE-2026-88807 UNKNOWN — A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients. Sep 21, 2026
CVE-2026-88806 HIGH 7.5 A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map. Sep 21, 2026
CVE-2026-85220 LOW 3.7 A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a Denial-of-Service attack against the honeypot. The vulnerability is … Sep 21, 2026
CVE-2025-71421 HIGH 7.2 UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role … Sep 21, 2026
CVE-2025-71420 MEDIUM 4.3 UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support … Sep 21, 2026
CVE-2025-71419 MEDIUM 5.4 UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject … Sep 21, 2026
CVE-2026-94383 UNKNOWN — The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension. The only sanitization applied was basename() to strip path … Sep 21, 2026
CVE-2026-94381 UNKNOWN — MISP has a security issue that can let a user gain more access than their API key is supposed to allow. A read-only API key … Sep 21, 2026
CVE-2026-94379 UNKNOWN — The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths. The original code used an allowlist approach, checking only … Sep 21, 2026
CVE-2026-94374 UNKNOWN — MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, the code iterates over EventReport … Sep 21, 2026
CVE-2026-94373 UNKNOWN — MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The ContextualMenu class populates HTML <option> elements by assigning user-controllable values … Sep 21, 2026
CVE-2026-94372 UNKNOWN — MISP contains a stored cross-site scripting (XSS) vulnerability in the default theme's Galaxies index page. When a MISP instance detects unknown custom or default galaxy … Sep 21, 2026
CVE-2026-94216 MEDIUM 4.3 A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This vulnerability affects the function authorize of the file … Sep 21, 2026