Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55714
Total
4403
Critical
16544
High
16275
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-94150 | LOW | 2.4 | A security flaw has been discovered in Omega Solution HRM OS up to 20260717. The impacted element is an unknown function of the file /media/view/ … | Sep 21, 2026 |
| CVE-2026-92400 | MEDIUM | 5.3 | The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured … | Sep 21, 2026 |
| CVE-2026-86802 | LOW | 3.7 | The To Do List Member WordPress plugin through 1.6 does not have authorisation or nonce checks in an import routine, and does not validate the … | Sep 21, 2026 |
| CVE-2026-85113 | MEDIUM | 6.5 | The GiveWP WordPress plugin before 4.16.9 does not remove shortcode delimiters from donor-supplied values before rendering them on public pages, and the shortcode stripping it … | Sep 21, 2026 |
| CVE-2026-85010 | MEDIUM | 5.3 | The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated … | Sep 21, 2026 |
| CVE-2026-15801 | HIGH | 8.0 | A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient … | Sep 21, 2026 |
| CVE-2025-12999 | UNKNOWN | — | UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, … | Sep 21, 2026 |
| CVE-2026-94149 | MEDIUM | 4.3 | A vulnerability was identified in Omega Solution HRM OS up to 20260717. The affected element is an unknown function of the file /role-permission/permission of the … | Sep 21, 2026 |
| CVE-2026-94148 | MEDIUM | 5.3 | A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function EmportDwr.createExportJSON of the file /ScadaBR/export_project.htm of the component Export Project Endpoint. This … | Sep 21, 2026 |
| CVE-2026-47321 | HIGH | 7.5 | The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting … | Sep 21, 2026 |
| CVE-2026-94218 | LOW | 3.1 | A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enforces a … | Sep 21, 2026 |
| CVE-2026-94217 | LOW | 3.5 | A flaw was found in the User-Managed Access (UMA) implementation of Keycloak. The issue occurs in the authorization token endpoint when processing permission tickets. If … | Sep 21, 2026 |
| CVE-2026-94215 | MEDIUM | 5.5 | A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the API uses … | Sep 21, 2026 |
| CVE-2026-94213 | MEDIUM | 4.9 | A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution. The issue occurs in the policy evaluation … | Sep 21, 2026 |
| CVE-2026-94146 | HIGH | 8.8 | A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. … | Sep 21, 2026 |
| CVE-2026-94145 | LOW | 3.5 | A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This vulnerability affects unknown code of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobInfoController.java of the component Task Management … | Sep 21, 2026 |
| CVE-2026-94144 | HIGH | 7.3 | A flaw has been found in drogonframework drogon up to 1.9.13. This affects the function makeCriteria in the library orm_lib/src/Criteria.cc of the component ORM. Executing … | Sep 21, 2026 |
| CVE-2026-90860 | HIGH | 7.1 | The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat … | Sep 21, 2026 |
| CVE-2026-82187 | CRITICAL | 9.8 | The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting … | Sep 21, 2026 |
| CVE-2026-94143 | HIGH | 7.3 | A vulnerability was detected in drogonframework drogon up to 1.9.13. Affected by this issue is the function Mapper::orderBy in the library Mapper.h of the component … | Sep 21, 2026 |
| CVE-2026-94142 | HIGH | 8.8 | A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of … | Sep 21, 2026 |
| CVE-2026-94139 | HIGH | 7.4 | A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_order.cgi?parameter=loginout of the component … | Sep 21, 2026 |
| CVE-2026-90839 | UNKNOWN | — | Rejected reason: this is rejected | Sep 21, 2026 |
| CVE-2026-94138 | MEDIUM | 6.6 | A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. This impacts an unknown function of the file /send_order.cgi?parameter=del_expmac. The manipulation … | Sep 21, 2026 |
| CVE-2026-94137 | LOW | 3.3 | A vulnerability was identified in Hangzhou Shunwang Technology shzh 10.7.2.693. This affects the function sub_180004AC0 of the file shdrv_x64.sys of the component IRP_MJ_DEVICE_CONTROL Handler. The … | Sep 21, 2026 |