Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56054
Total
4437
Critical
16638
High
16408
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-94412 | HIGH | 8.8 | jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticated users to reset any other user's password. Attackers can … | Sep 21, 2026 |
| CVE-2026-94411 | HIGH | 8.8 | jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbitrary roles. Attackers can send a POST … | Sep 21, 2026 |
| CVE-2026-94403 | HIGH | 8.8 | A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library ene.sys of the component IOCTL Handler. This manipulation … | Sep 21, 2026 |
| CVE-2026-91167 | UNKNOWN | — | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.28.4, PUT /@warpgate/admin/api/users/:id/roles/:role_id reaches api_update_user_role in warpgate-admin/src/api/users.rs through AdminContext but … | Sep 21, 2026 |
| CVE-2026-91166 | MEDIUM | 5.7 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path in warpgate-web-ssh/src/manager.rs handles RCEvent::HostKeyUnknown … | Sep 21, 2026 |
| CVE-2026-91165 | LOW | 2.4 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.27.6, the response_mode=form_post SSO return path in warpgate-protocol-http/src/api/sso_provider_list.rs uses serde_json::to_string … | Sep 21, 2026 |
| CVE-2026-91164 | MEDIUM | 4.3 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API token authentication resolves ConfigProvider::validate_api_token into RequestAuthorization::UserToken … | Sep 21, 2026 |
| CVE-2026-82165 | MEDIUM | 5.5 | Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access … | Sep 21, 2026 |
| CVE-2026-82163 | MEDIUM | 5.5 | Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access … | Sep 21, 2026 |
| CVE-2026-66280 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 21, 2026 |
| CVE-2026-63330 | HIGH | 7.7 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_stream in warpgate-admin/src/api/recordings_detail.rs protects /@warpgate/admin/api/recordings/{uuid}/stream only with session authentication … | Sep 21, 2026 |
| CVE-2026-63329 | MEDIUM | 4.9 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request in warpgate-protocol-http/src/proxy.rs forwards a client-supplied x-warpgate-username header before … | Sep 21, 2026 |
| CVE-2026-61749 | MEDIUM | 6.5 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author report or label templates can cause WeasyPrint report … | Sep 21, 2026 |
| CVE-2026-61748 | MEDIUM | 4.3 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, ReportPrint at POST /api/report/print/ and LabelPrint at POST /api/report/label/print/ require authentication but do not … | Sep 21, 2026 |
| CVE-2026-61747 | MEDIUM | 4.3 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the /api/importer/row/ and /api/importer/mapping/ endpoints do not scope DataImportRow and DataImportColumnMap querysets to the … | Sep 21, 2026 |
| CVE-2026-61746 | MEDIUM | 5.3 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingList, and PluginSettingDetail set GlobalSettingsPermissions without the IsAuthenticated permission used by the project … | Sep 21, 2026 |
| CVE-2026-61744 | MEDIUM | 6.5 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacker-synthesized internal JSON barcode containing a lowercase model label and … | Sep 21, 2026 |
| CVE-2026-58491 | CRITICAL | 9.3 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start endpoint stores an attacker-controlled next parameter that … | Sep 21, 2026 |
| CVE-2026-49810 | HIGH | 7.8 | Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local … | Sep 21, 2026 |
| CVE-2026-17052 | HIGH | 7.8 | The Time-aware GPIO syscall verification handler z_vrfy_tgpio_pin_read_ts_ec() in drivers/timeaware_gpio/timeaware_gpio_handlers.c validated only the port device object and passed the caller-supplied timestamp and event_count output pointers to … | Sep 21, 2026 |
| CVE-2026-94488 | HIGH | 8.2 | Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot … | Sep 21, 2026 |
| CVE-2026-93012 | UNKNOWN | — | Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe. On MSWin32 … | Sep 21, 2026 |
| CVE-2026-92382 | MEDIUM | 4.1 | An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer … | Sep 21, 2026 |
| CVE-2026-69190 | MEDIUM | 6.3 | Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for saved searches and dashboards … | Sep 21, 2026 |
| CVE-2026-62369 | HIGH | 8.1 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.16.0 until 1.21.2, 1.22.2, and 1.23.1, the … | Sep 21, 2026 |