Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56054
Total
4437
Critical
16638
High
16408
Medium
CVE ID Severity Score Description Published
CVE-2026-94382 MEDIUM 4.2 Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or … Sep 21, 2026
CVE-2026-93884 UNKNOWN — Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this … Sep 21, 2026
CVE-2026-88807 UNKNOWN — A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients. Sep 21, 2026
CVE-2026-88806 HIGH 7.5 A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map. Sep 21, 2026
CVE-2026-85220 LOW 3.7 A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a Denial-of-Service attack against the honeypot. The vulnerability is … Sep 21, 2026
CVE-2025-71421 HIGH 7.2 UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role … Sep 21, 2026
CVE-2025-71420 MEDIUM 4.3 UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support … Sep 21, 2026
CVE-2025-71419 MEDIUM 5.4 UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject … Sep 21, 2026
CVE-2026-94383 UNKNOWN — The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension. The only sanitization applied was basename() to strip path … Sep 21, 2026
CVE-2026-94381 UNKNOWN — MISP has a security issue that can let a user gain more access than their API key is supposed to allow. A read-only API key … Sep 21, 2026
CVE-2026-94379 UNKNOWN — The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths. The original code used an allowlist approach, checking only … Sep 21, 2026
CVE-2026-94374 UNKNOWN — MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, the code iterates over EventReport … Sep 21, 2026
CVE-2026-94373 UNKNOWN — MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The ContextualMenu class populates HTML <option> elements by assigning user-controllable values … Sep 21, 2026
CVE-2026-94372 UNKNOWN — MISP contains a stored cross-site scripting (XSS) vulnerability in the default theme's Galaxies index page. When a MISP instance detects unknown custom or default galaxy … Sep 21, 2026
CVE-2026-94216 MEDIUM 4.3 A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This vulnerability affects the function authorize of the file … Sep 21, 2026
CVE-2026-94214 MEDIUM 4.3 A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the file /login.html … Sep 21, 2026
CVE-2026-94211 LOW 2.4 A vulnerability has been found in Hyve5 Leantime up to 3.9.8. Affected by this issue is some unknown functionality of the file /app/Domain/Dashboard/Templates/show.blade.php of the … Sep 21, 2026
CVE-2026-84285 HIGH 8.8 An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server. Sep 21, 2026
CVE-2026-94368 HIGH 7.1 A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway. The issue occurs when the … Sep 21, 2026
CVE-2026-94210 LOW 3.5 A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the file app/Domain/Tickets/Services/Tickets.php of the … Sep 21, 2026
CVE-2026-91867 MEDIUM 4.3 When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly … Sep 21, 2026
CVE-2026-91866 HIGH 7.5 A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial … Sep 21, 2026
CVE-2026-91865 HIGH 7.5 A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and … Sep 21, 2026
CVE-2026-91864 HIGH 7.5 A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, … Sep 21, 2026
CVE-2026-91863 HIGH 7.5 A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of … Sep 21, 2026