Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56054
Total
4437
Critical
16638
High
16408
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-73549 | MEDIUM | 5.3 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's Utility::copyInternetAddressAndPort and QUIC client-address … | Sep 21, 2026 |
| CVE-2026-73548 | HIGH | 7.5 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy forwards data for a … | Sep 21, 2026 |
| CVE-2026-73547 | HIGH | 7.5 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ext_authz filter assumes that … | Sep 21, 2026 |
| CVE-2026-73546 | HIGH | 7.4 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's /stats?format=html admin endpoint uses … | Sep 21, 2026 |
| CVE-2026-73513 | HIGH | 7.5 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's optional oghttp2 upstream HTTP/2 … | Sep 21, 2026 |
| CVE-2026-73512 | HIGH | 7.5 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HttpDatagramHandler caches the current … | Sep 21, 2026 |
| CVE-2026-62247 | MEDIUM | 6.5 | Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets. Prior to 2.111.2, Realtime authorization does not correctly honor the per-extension presence.read row-level security policy … | Sep 21, 2026 |
| CVE-2026-58271 | MEDIUM | 6.8 | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/app/sync/register` accepts credentials and a TOTP code … | Sep 21, 2026 |
| CVE-2026-58269 | HIGH | 8.1 | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/auth/token` authenticates with username and password only, … | Sep 21, 2026 |
| CVE-2026-55897 | HIGH | 8.8 | luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot … | Sep 21, 2026 |
| CVE-2026-55159 | HIGH | 8.8 | luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts … | Sep 21, 2026 |
| CVE-2026-54915 | MEDIUM | 5.4 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the unauthenticated /auth/redirect endpoint in plexpy/webauth.py removes forward slashes … | Sep 21, 2026 |
| CVE-2026-52835 | UNKNOWN | — | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the import_config handler and the database_file branch of import_database … | Sep 21, 2026 |
| CVE-2026-50572 | MEDIUM | 5.9 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HTTP external-authorization client can … | Sep 21, 2026 |
| CVE-2026-49995 | UNKNOWN | — | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the newsletter cron field stored in the newsletters table … | Sep 21, 2026 |
| CVE-2026-49811 | HIGH | 8.4 | Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access … | Sep 21, 2026 |
| CVE-2026-48521 | MEDIUM | 5.9 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ProdClusterManagerFactory::allocateConnPool dereferences transport_socket_options while … | Sep 21, 2026 |
| CVE-2026-45381 | UNKNOWN | — | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search endpoint inserts its user-controlled query parameter into … | Sep 21, 2026 |
| CVE-2026-94501 | HIGH | 8.8 | jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without … | Sep 21, 2026 |
| CVE-2026-94497 | HIGH | 8.3 | jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and … | Sep 21, 2026 |
| CVE-2026-94496 | HIGH | 8.3 | jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify any role's data scope or delete roles. Attackers … | Sep 21, 2026 |
| CVE-2026-94495 | HIGH | 7.1 | jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticated users to modify tenant system configuration. Attackers can rewrite or delete tenant-wide … | Sep 21, 2026 |
| CVE-2026-94494 | MEDIUM | 5.0 | jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info endpoint. Attackers can … | Sep 21, 2026 |
| CVE-2026-94414 | MEDIUM | 5.4 | jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticated users to modify role button-permission definitions. Attackers can supply … | Sep 21, 2026 |
| CVE-2026-94413 | MEDIUM | 6.5 | jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve unsalted MD5 password digests for any user. Attackers … | Sep 21, 2026 |