Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56054
Total
4437
Critical
16638
High
16408
Medium
CVE ID Severity Score Description Published
CVE-2026-73549 MEDIUM 5.3 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's Utility::copyInternetAddressAndPort and QUIC client-address … Sep 21, 2026
CVE-2026-73548 HIGH 7.5 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy forwards data for a … Sep 21, 2026
CVE-2026-73547 HIGH 7.5 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ext_authz filter assumes that … Sep 21, 2026
CVE-2026-73546 HIGH 7.4 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's /stats?format=html admin endpoint uses … Sep 21, 2026
CVE-2026-73513 HIGH 7.5 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's optional oghttp2 upstream HTTP/2 … Sep 21, 2026
CVE-2026-73512 HIGH 7.5 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HttpDatagramHandler caches the current … Sep 21, 2026
CVE-2026-62247 MEDIUM 6.5 Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets. Prior to 2.111.2, Realtime authorization does not correctly honor the per-extension presence.read row-level security policy … Sep 21, 2026
CVE-2026-58271 MEDIUM 6.8 Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/app/sync/register` accepts credentials and a TOTP code … Sep 21, 2026
CVE-2026-58269 HIGH 8.1 Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/auth/token` authenticates with username and password only, … Sep 21, 2026
CVE-2026-55897 HIGH 8.8 luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot … Sep 21, 2026
CVE-2026-55159 HIGH 8.8 luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts … Sep 21, 2026
CVE-2026-54915 MEDIUM 5.4 Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the unauthenticated /auth/redirect endpoint in plexpy/webauth.py removes forward slashes … Sep 21, 2026
CVE-2026-52835 UNKNOWN — Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the import_config handler and the database_file branch of import_database … Sep 21, 2026
CVE-2026-50572 MEDIUM 5.9 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HTTP external-authorization client can … Sep 21, 2026
CVE-2026-49995 UNKNOWN — Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the newsletter cron field stored in the newsletters table … Sep 21, 2026
CVE-2026-49811 HIGH 8.4 Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access … Sep 21, 2026
CVE-2026-48521 MEDIUM 5.9 Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ProdClusterManagerFactory::allocateConnPool dereferences transport_socket_options while … Sep 21, 2026
CVE-2026-45381 UNKNOWN — Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search endpoint inserts its user-controlled query parameter into … Sep 21, 2026
CVE-2026-94501 HIGH 8.8 jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without … Sep 21, 2026
CVE-2026-94497 HIGH 8.3 jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and … Sep 21, 2026
CVE-2026-94496 HIGH 8.3 jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify any role's data scope or delete roles. Attackers … Sep 21, 2026
CVE-2026-94495 HIGH 7.1 jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticated users to modify tenant system configuration. Attackers can rewrite or delete tenant-wide … Sep 21, 2026
CVE-2026-94494 MEDIUM 5.0 jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info endpoint. Attackers can … Sep 21, 2026
CVE-2026-94414 MEDIUM 5.4 jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticated users to modify role button-permission definitions. Attackers can supply … Sep 21, 2026
CVE-2026-94413 MEDIUM 6.5 jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve unsalted MD5 password digests for any user. Attackers … Sep 21, 2026