Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55714
Total
4403
Critical
16544
High
16275
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-92252 | UNKNOWN | — | Incorrect default permissions in the installation directory of WatchDog Anti-Virus on Windows allow local, low-privileged users to modify, replace, or delete antivirus binaries and configuration … | Sep 20, 2026 |
| CVE-2026-90817 | CRITICAL | 9.8 | An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially … | Sep 20, 2026 |
| CVE-2026-94113 | MEDIUM | 6.5 | Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in whitelisted timesheet endpoints that fail to enforce doctype permissions. Authenticated … | Sep 20, 2026 |
| CVE-2026-94112 | MEDIUM | 6.8 | mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured codes within the acceptance window. Attackers with stolen credentials … | Sep 20, 2026 |
| CVE-2026-94111 | MEDIUM | 6.6 | Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in … | Sep 20, 2026 |
| CVE-2026-94109 | HIGH | 8.8 | openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration. Authenticated attackers can inject malicious … | Sep 20, 2026 |
| CVE-2026-94108 | MEDIUM | 6.5 | getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to properly disable entity loading on PHP before … | Sep 20, 2026 |
| CVE-2026-94107 | HIGH | 8.1 | NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10). Attackers who know … | Sep 20, 2026 |
| CVE-2026-94106 | HIGH | 8.8 | getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames … | Sep 20, 2026 |
| CVE-2026-94105 | MEDIUM | 5.3 | NivoCart through 2.4.0 contains a destructive configuration write vulnerability in the admin password reset controller that allows unauthenticated attackers to disable password recovery by supplying … | Sep 20, 2026 |
| CVE-2026-94104 | HIGH | 8.8 | NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new filenames or … | Sep 20, 2026 |
| CVE-2026-94004 | HIGH | 7.3 | A vulnerability was found in DedeCMS up to 5.7.118. The affected element is an unknown function of the file plus/mytag_js.php. The manipulation of the argument … | Sep 20, 2026 |
| CVE-2026-94003 | CRITICAL | 10.0 | A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The … | Sep 20, 2026 |
| CVE-2026-93997 | HIGH | 7.3 | A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected by this issue is some unknown functionality of the file /Admin/edit_symptom.php. This manipulation … | Sep 20, 2026 |
| CVE-2026-93980 | HIGH | 7.3 | A weakness has been identified in code-projects Internship Management System 1.0. This vulnerability affects unknown code of the file /admin/login.php of the component Admin Login … | Sep 20, 2026 |
| CVE-2026-93979 | HIGH | 7.3 | A security flaw has been discovered in code-projects Internship Management System 1.0. This affects an unknown part of the file /employer/login.php. Performing a manipulation of … | Sep 20, 2026 |
| CVE-2026-93978 | HIGH | 7.3 | A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of … | Sep 20, 2026 |
| CVE-2026-93977 | LOW | 3.5 | A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this vulnerability is an unknown functionality of the file lecturer/add-single-mark.php. This manipulation of the … | Sep 20, 2026 |
| CVE-2026-93976 | LOW | 2.4 | A vulnerability was found in code-projects Assessment Management 1.0. Affected is an unknown function of the file admin/add-user.php. The manipulation of the argument level results … | Sep 20, 2026 |
| CVE-2026-93975 | LOW | 2.4 | A vulnerability has been found in code-projects Assessment Management 1.0. This impacts an unknown function of the file admin/edit-user.php of the component User Editing. The … | Sep 20, 2026 |
| CVE-2026-86555 | MEDIUM | 6.2 | The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the … | Sep 20, 2026 |
| CVE-2026-93974 | HIGH | 7.3 | A flaw has been found in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=remove. Executing a manipulation of … | Sep 20, 2026 |
| CVE-2026-93973 | HIGH | 7.3 | A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/subject/btn_functions.php?action=remove. Performing a manipulation … | Sep 20, 2026 |
| CVE-2026-93972 | HIGH | 7.3 | A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/course/btn_functions.php. Such … | Sep 20, 2026 |
| CVE-2026-93971 | MEDIUM | 5.3 | A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted is an unknown function of the file backend/sxdevops/settings.py. This manipulation causes information disclosure. It is … | Sep 20, 2026 |