Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56054
Total
4437
Critical
16638
High
16408
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-89139 | UNKNOWN | — | Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to … | Sep 21, 2026 |
| CVE-2026-87858 | UNKNOWN | — | Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header. An authenticated caller holding only write permission in a … | Sep 21, 2026 |
| CVE-2026-65654 | UNKNOWN | — | github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's labels, but affected versions do not apply those limits to label maps received … | Sep 21, 2026 |
| CVE-2026-65653 | UNKNOWN | — | github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-prefixed argument chunks. The fragment reader left its chunk slice empty and then … | Sep 21, 2026 |
| CVE-2026-65652 | UNKNOWN | — | github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames. A network peer that can reach a listener can complete the standard … | Sep 21, 2026 |
| CVE-2026-65651 | UNKNOWN | — | temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's … | Sep 21, 2026 |
| CVE-2026-16652 | UNKNOWN | — | Temporal Server did not bound the work performed while searching for a Schedule's next action time. An authenticated caller with namespace write permission could create … | Sep 21, 2026 |
| CVE-2026-16651 | UNKNOWN | — | temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents are empty or consist only of one to five decimal … | Sep 21, 2026 |
| CVE-2026-92612 | UNKNOWN | — | In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a … | Sep 21, 2026 |
| CVE-2026-77021 | UNKNOWN | — | Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for … | Sep 21, 2026 |
| CVE-2026-94277 | UNKNOWN | — | MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into HTML output via sprintf() without any HTML encoding. An authenticated user holding the … | Sep 21, 2026 |
| CVE-2026-92574 | HIGH | 8.8 | A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security … | Sep 21, 2026 |
| CVE-2026-91921 | UNKNOWN | — | Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitisation in the client-side rendering engine of the 1millionbot AI Chat Platform. An unauthenticated remote user could … | Sep 21, 2026 |
| CVE-2026-94152 | MEDIUM | 4.3 | A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown function of the file /user/ of the … | Sep 21, 2026 |
| CVE-2026-94151 | MEDIUM | 5.3 | A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /role-permission/permission of the component … | Sep 21, 2026 |
| CVE-2026-94150 | LOW | 2.4 | A security flaw has been discovered in Omega Solution HRM OS up to 20260717. The impacted element is an unknown function of the file /media/view/ … | Sep 21, 2026 |
| CVE-2026-92400 | MEDIUM | 5.3 | The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured … | Sep 21, 2026 |
| CVE-2026-86802 | LOW | 3.7 | The To Do List Member WordPress plugin through 1.6 does not have authorisation or nonce checks in an import routine, and does not validate the … | Sep 21, 2026 |
| CVE-2026-85113 | MEDIUM | 6.5 | The GiveWP WordPress plugin before 4.16.9 does not remove shortcode delimiters from donor-supplied values before rendering them on public pages, and the shortcode stripping it … | Sep 21, 2026 |
| CVE-2026-85010 | MEDIUM | 5.3 | The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated … | Sep 21, 2026 |
| CVE-2026-15801 | HIGH | 8.0 | A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient … | Sep 21, 2026 |
| CVE-2025-12999 | UNKNOWN | — | UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, … | Sep 21, 2026 |
| CVE-2026-94149 | MEDIUM | 4.3 | A vulnerability was identified in Omega Solution HRM OS up to 20260717. The affected element is an unknown function of the file /role-permission/permission of the … | Sep 21, 2026 |
| CVE-2026-94148 | MEDIUM | 5.3 | A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function EmportDwr.createExportJSON of the file /ScadaBR/export_project.htm of the component Export Project Endpoint. This … | Sep 21, 2026 |
| CVE-2026-47321 | HIGH | 7.5 | The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting … | Sep 21, 2026 |