Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56054
Total
4437
Critical
16638
High
16408
Medium
CVE ID Severity Score Description Published
CVE-2026-94412 HIGH 8.8 jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticated users to reset any other user's password. Attackers can … Sep 21, 2026
CVE-2026-94411 HIGH 8.8 jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbitrary roles. Attackers can send a POST … Sep 21, 2026
CVE-2026-94403 HIGH 8.8 A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library ene.sys of the component IOCTL Handler. This manipulation … Sep 21, 2026
CVE-2026-91167 UNKNOWN — Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.28.4, PUT /@warpgate/admin/api/users/:id/roles/:role_id reaches api_update_user_role in warpgate-admin/src/api/users.rs through AdminContext but … Sep 21, 2026
CVE-2026-91166 MEDIUM 5.7 Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path in warpgate-web-ssh/src/manager.rs handles RCEvent::HostKeyUnknown … Sep 21, 2026
CVE-2026-91165 LOW 2.4 Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.27.6, the response_mode=form_post SSO return path in warpgate-protocol-http/src/api/sso_provider_list.rs uses serde_json::to_string … Sep 21, 2026
CVE-2026-91164 MEDIUM 4.3 Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API token authentication resolves ConfigProvider::validate_api_token into RequestAuthorization::UserToken … Sep 21, 2026
CVE-2026-82165 MEDIUM 5.5 Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access … Sep 21, 2026
CVE-2026-82163 MEDIUM 5.5 Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access … Sep 21, 2026
CVE-2026-66280 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Sep 21, 2026
CVE-2026-63330 HIGH 7.7 Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_stream in warpgate-admin/src/api/recordings_detail.rs protects /@warpgate/admin/api/recordings/{uuid}/stream only with session authentication … Sep 21, 2026
CVE-2026-63329 MEDIUM 4.9 Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request in warpgate-protocol-http/src/proxy.rs forwards a client-supplied x-warpgate-username header before … Sep 21, 2026
CVE-2026-61749 MEDIUM 6.5 InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author report or label templates can cause WeasyPrint report … Sep 21, 2026
CVE-2026-61748 MEDIUM 4.3 InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, ReportPrint at POST /api/report/print/ and LabelPrint at POST /api/report/label/print/ require authentication but do not … Sep 21, 2026
CVE-2026-61747 MEDIUM 4.3 InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the /api/importer/row/ and /api/importer/mapping/ endpoints do not scope DataImportRow and DataImportColumnMap querysets to the … Sep 21, 2026
CVE-2026-61746 MEDIUM 5.3 InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingList, and PluginSettingDetail set GlobalSettingsPermissions without the IsAuthenticated permission used by the project … Sep 21, 2026
CVE-2026-61744 MEDIUM 6.5 InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacker-synthesized internal JSON barcode containing a lowercase model label and … Sep 21, 2026
CVE-2026-58491 CRITICAL 9.3 Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start endpoint stores an attacker-controlled next parameter that … Sep 21, 2026
CVE-2026-49810 HIGH 7.8 Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local … Sep 21, 2026
CVE-2026-17052 HIGH 7.8 The Time-aware GPIO syscall verification handler z_vrfy_tgpio_pin_read_ts_ec() in drivers/timeaware_gpio/timeaware_gpio_handlers.c validated only the port device object and passed the caller-supplied timestamp and event_count output pointers to … Sep 21, 2026
CVE-2026-94488 HIGH 8.2 Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot … Sep 21, 2026
CVE-2026-93012 UNKNOWN — Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe. On MSWin32 … Sep 21, 2026
CVE-2026-92382 MEDIUM 4.1 An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer … Sep 21, 2026
CVE-2026-69190 MEDIUM 6.3 Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for saved searches and dashboards … Sep 21, 2026
CVE-2026-62369 HIGH 8.1 KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.16.0 until 1.21.2, 1.22.2, and 1.23.1, the … Sep 21, 2026