Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56054
Total
4437
Critical
16638
High
16408
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-94382 | MEDIUM | 4.2 | Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or … | Sep 21, 2026 |
| CVE-2026-93884 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this … | Sep 21, 2026 |
| CVE-2026-88807 | UNKNOWN | — | A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients. | Sep 21, 2026 |
| CVE-2026-88806 | HIGH | 7.5 | A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map. | Sep 21, 2026 |
| CVE-2026-85220 | LOW | 3.7 | A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a Denial-of-Service attack against the honeypot. The vulnerability is … | Sep 21, 2026 |
| CVE-2025-71421 | HIGH | 7.2 | UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role … | Sep 21, 2026 |
| CVE-2025-71420 | MEDIUM | 4.3 | UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support … | Sep 21, 2026 |
| CVE-2025-71419 | MEDIUM | 5.4 | UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject … | Sep 21, 2026 |
| CVE-2026-94383 | UNKNOWN | — | The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension. The only sanitization applied was basename() to strip path … | Sep 21, 2026 |
| CVE-2026-94381 | UNKNOWN | — | MISP has a security issue that can let a user gain more access than their API key is supposed to allow. A read-only API key … | Sep 21, 2026 |
| CVE-2026-94379 | UNKNOWN | — | The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths. The original code used an allowlist approach, checking only … | Sep 21, 2026 |
| CVE-2026-94374 | UNKNOWN | — | MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, the code iterates over EventReport … | Sep 21, 2026 |
| CVE-2026-94373 | UNKNOWN | — | MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The ContextualMenu class populates HTML <option> elements by assigning user-controllable values … | Sep 21, 2026 |
| CVE-2026-94372 | UNKNOWN | — | MISP contains a stored cross-site scripting (XSS) vulnerability in the default theme's Galaxies index page. When a MISP instance detects unknown custom or default galaxy … | Sep 21, 2026 |
| CVE-2026-94216 | MEDIUM | 4.3 | A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This vulnerability affects the function authorize of the file … | Sep 21, 2026 |
| CVE-2026-94214 | MEDIUM | 4.3 | A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the file /login.html … | Sep 21, 2026 |
| CVE-2026-94211 | LOW | 2.4 | A vulnerability has been found in Hyve5 Leantime up to 3.9.8. Affected by this issue is some unknown functionality of the file /app/Domain/Dashboard/Templates/show.blade.php of the … | Sep 21, 2026 |
| CVE-2026-84285 | HIGH | 8.8 | An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server. | Sep 21, 2026 |
| CVE-2026-94368 | HIGH | 7.1 | A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway. The issue occurs when the … | Sep 21, 2026 |
| CVE-2026-94210 | LOW | 3.5 | A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the file app/Domain/Tickets/Services/Tickets.php of the … | Sep 21, 2026 |
| CVE-2026-91867 | MEDIUM | 4.3 | When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly … | Sep 21, 2026 |
| CVE-2026-91866 | HIGH | 7.5 | A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial … | Sep 21, 2026 |
| CVE-2026-91865 | HIGH | 7.5 | A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and … | Sep 21, 2026 |
| CVE-2026-91864 | HIGH | 7.5 | A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, … | Sep 21, 2026 |
| CVE-2026-91863 | HIGH | 7.5 | A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of … | Sep 21, 2026 |