Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56054
Total
4437
Critical
16638
High
16408
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-59168 | MEDIUM | 6.2 | Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.1, parsing/json/json_reader.go decodeValue, decodeObject, and decodeArray, and parsing/xml/reader.go … | Sep 21, 2026 |
| CVE-2026-58504 | MEDIUM | 6.1 | draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.5, opening or importing a crafted .drawio file can execute attacker-controlled JavaScript in the … | Sep 21, 2026 |
| CVE-2026-17051 | MEDIUM | 6.0 | The Intel SEDI IPM (inter-processor mailbox) driver in drivers/ipm/ipm_sedi.c handles an inbound message interrupt in ipm_event_dispose(). It read the peer-written doorbell register, extracted the payload … | Sep 21, 2026 |
| CVE-2026-17050 | MEDIUM | 5.7 | The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicated usb_device_heap in usbh_device_set_configuration() (subsys/usb/host/usbh_device.c). On three failure paths — a failed … | Sep 21, 2026 |
| CVE-2026-88978 | MEDIUM | 4.3 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, the WorkerStatus gRPC polling path in pkg/repository/durable_events.go … | Sep 21, 2026 |
| CVE-2026-85751 | CRITICAL | 9.8 | Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with … | Sep 21, 2026 |
| CVE-2026-84298 | LOW | 3.1 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.95.3, the V1 DurableTask stream handler stores worker-supplied … | Sep 21, 2026 |
| CVE-2026-82412 | HIGH | 8.8 | ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept the scan_ports parameter without an administrator gate … | Sep 21, 2026 |
| CVE-2026-77166 | LOW | 2.4 | The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout … | Sep 21, 2026 |
| CVE-2026-77165 | MEDIUM | 6.5 | File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database. | Sep 21, 2026 |
| CVE-2026-63342 | MEDIUM | 6.3 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, api-contracts/openapi/paths/v1/workflow-runs/workflow_run.yaml defines the GET /api/v1/stable/durable-tasks/{durable-task} endpoint implemented … | Sep 21, 2026 |
| CVE-2026-61687 | HIGH | 7.1 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to … | Sep 21, 2026 |
| CVE-2026-61681 | MEDIUM | 4.1 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, the SNS UnsubscribeConfirmation handler in internal/integrations/ingestors/sns/sns.go calls … | Sep 21, 2026 |
| CVE-2026-55563 | UNKNOWN | — | Feast is the open source feature store for AI and machine learning. Prior to 0.65.0, .github/workflows/pr_integration_tests.yml uses pull_request_target with the synchronize event and preserves ok-to-test, … | Sep 21, 2026 |
| CVE-2026-53940 | HIGH | 8.8 | Conda is a system-level binary package and environment manager that runs on major operating systems and platforms. Prior to 26.5.2, parse_entry_point_def in conda/common/path/python.py accepted an … | Sep 21, 2026 |
| CVE-2026-36472 | MEDIUM | 5.2 | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allows a remote attacker to execute arbitrary JavaScript in … | Sep 21, 2026 |
| CVE-2026-36471 | UNKNOWN | — | Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker to inject arbitrary values into internal request variables … | Sep 21, 2026 |
| CVE-2026-36470 | UNKNOWN | — | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied into the response HTML unmodified/unescaped during … | Sep 21, 2026 |
| CVE-2026-36469 | UNKNOWN | — | CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Media Manager's "Upload by URL" functionality). | Sep 21, 2026 |
| CVE-2026-36468 | MEDIUM | 6.1 | Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitrarily named URL parameter key, with part of its name … | Sep 21, 2026 |
| CVE-2026-36467 | HIGH | 7.2 | Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute … | Sep 21, 2026 |
| CVE-2026-94301 | CRITICAL | 9.8 | The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 … | Sep 21, 2026 |
| CVE-2026-94184 | HIGH | 8.1 | A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send … | Sep 21, 2026 |
| CVE-2026-93339 | MEDIUM | 5.4 | Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that allows authenticated users with Author-level privileges or higher to inject arbitrary HTML … | Sep 21, 2026 |
| CVE-2026-86473 | CRITICAL | 9.1 | Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential … | Sep 21, 2026 |