Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55714
Total
4403
Critical
16544
High
16275
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-94214 | MEDIUM | 4.3 | A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the file /login.html … | Sep 21, 2026 |
| CVE-2026-94211 | LOW | 2.4 | A vulnerability has been found in Hyve5 Leantime up to 3.9.8. Affected by this issue is some unknown functionality of the file /app/Domain/Dashboard/Templates/show.blade.php of the … | Sep 21, 2026 |
| CVE-2026-84285 | HIGH | 8.8 | An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server. | Sep 21, 2026 |
| CVE-2026-94368 | HIGH | 7.1 | A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway. The issue occurs when the … | Sep 21, 2026 |
| CVE-2026-94210 | LOW | 3.5 | A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the file app/Domain/Tickets/Services/Tickets.php of the … | Sep 21, 2026 |
| CVE-2026-91867 | MEDIUM | 4.3 | When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly … | Sep 21, 2026 |
| CVE-2026-91866 | HIGH | 7.5 | A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial … | Sep 21, 2026 |
| CVE-2026-91865 | HIGH | 7.5 | A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and … | Sep 21, 2026 |
| CVE-2026-91864 | HIGH | 7.5 | A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, … | Sep 21, 2026 |
| CVE-2026-91863 | HIGH | 7.5 | A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of … | Sep 21, 2026 |
| CVE-2026-89139 | UNKNOWN | — | Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to … | Sep 21, 2026 |
| CVE-2026-87858 | UNKNOWN | — | Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header. An authenticated caller holding only write permission in a … | Sep 21, 2026 |
| CVE-2026-65654 | UNKNOWN | — | github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's labels, but affected versions do not apply those limits to label maps received … | Sep 21, 2026 |
| CVE-2026-65653 | UNKNOWN | — | github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-prefixed argument chunks. The fragment reader left its chunk slice empty and then … | Sep 21, 2026 |
| CVE-2026-65652 | UNKNOWN | — | github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames. A network peer that can reach a listener can complete the standard … | Sep 21, 2026 |
| CVE-2026-65651 | UNKNOWN | — | temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's … | Sep 21, 2026 |
| CVE-2026-16652 | UNKNOWN | — | Temporal Server did not bound the work performed while searching for a Schedule's next action time. An authenticated caller with namespace write permission could create … | Sep 21, 2026 |
| CVE-2026-16651 | UNKNOWN | — | temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents are empty or consist only of one to five decimal … | Sep 21, 2026 |
| CVE-2026-92612 | UNKNOWN | — | In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a … | Sep 21, 2026 |
| CVE-2026-77021 | UNKNOWN | — | Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for … | Sep 21, 2026 |
| CVE-2026-94277 | UNKNOWN | — | MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into HTML output via sprintf() without any HTML encoding. An authenticated user holding the … | Sep 21, 2026 |
| CVE-2026-92574 | HIGH | 8.8 | A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security … | Sep 21, 2026 |
| CVE-2026-91921 | UNKNOWN | — | Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitisation in the client-side rendering engine of the 1millionbot AI Chat Platform. An unauthenticated remote user could … | Sep 21, 2026 |
| CVE-2026-94152 | MEDIUM | 4.3 | A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown function of the file /user/ of the … | Sep 21, 2026 |
| CVE-2026-94151 | MEDIUM | 5.3 | A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /role-permission/permission of the component … | Sep 21, 2026 |