Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

55714
Total
4403
Critical
16544
High
16275
Medium
CVE ID Severity Score Description Published
CVE-2026-94214 MEDIUM 4.3 A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the file /login.html … Sep 21, 2026
CVE-2026-94211 LOW 2.4 A vulnerability has been found in Hyve5 Leantime up to 3.9.8. Affected by this issue is some unknown functionality of the file /app/Domain/Dashboard/Templates/show.blade.php of the … Sep 21, 2026
CVE-2026-84285 HIGH 8.8 An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server. Sep 21, 2026
CVE-2026-94368 HIGH 7.1 A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway. The issue occurs when the … Sep 21, 2026
CVE-2026-94210 LOW 3.5 A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the file app/Domain/Tickets/Services/Tickets.php of the … Sep 21, 2026
CVE-2026-91867 MEDIUM 4.3 When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly … Sep 21, 2026
CVE-2026-91866 HIGH 7.5 A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial … Sep 21, 2026
CVE-2026-91865 HIGH 7.5 A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and … Sep 21, 2026
CVE-2026-91864 HIGH 7.5 A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, … Sep 21, 2026
CVE-2026-91863 HIGH 7.5 A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of … Sep 21, 2026
CVE-2026-89139 UNKNOWN — Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to … Sep 21, 2026
CVE-2026-87858 UNKNOWN — Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header. An authenticated caller holding only write permission in a … Sep 21, 2026
CVE-2026-65654 UNKNOWN — github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's labels, but affected versions do not apply those limits to label maps received … Sep 21, 2026
CVE-2026-65653 UNKNOWN — github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-prefixed argument chunks. The fragment reader left its chunk slice empty and then … Sep 21, 2026
CVE-2026-65652 UNKNOWN — github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames. A network peer that can reach a listener can complete the standard … Sep 21, 2026
CVE-2026-65651 UNKNOWN — temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's … Sep 21, 2026
CVE-2026-16652 UNKNOWN — Temporal Server did not bound the work performed while searching for a Schedule's next action time. An authenticated caller with namespace write permission could create … Sep 21, 2026
CVE-2026-16651 UNKNOWN — temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents are empty or consist only of one to five decimal … Sep 21, 2026
CVE-2026-92612 UNKNOWN — In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a … Sep 21, 2026
CVE-2026-77021 UNKNOWN — Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for … Sep 21, 2026
CVE-2026-94277 UNKNOWN — MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into HTML output via sprintf() without any HTML encoding. An authenticated user holding the … Sep 21, 2026
CVE-2026-92574 HIGH 8.8 A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security … Sep 21, 2026
CVE-2026-91921 UNKNOWN — Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitisation in the client-side rendering engine of the 1millionbot AI Chat Platform. An unauthenticated remote user could … Sep 21, 2026
CVE-2026-94152 MEDIUM 4.3 A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown function of the file /user/ of the … Sep 21, 2026
CVE-2026-94151 MEDIUM 5.3 A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /role-permission/permission of the component … Sep 21, 2026