Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56102
Total
4437
Critical
16640
High
16418
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-93958 | CRITICAL | 9.1 | A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of … | Sep 20, 2026 |
| CVE-2026-93957 | MEDIUM | 4.3 | A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This affects the function SearchEngine::matchesSingleFilter of the file src/SearchEngine.php of the component Filter Matching. … | Sep 20, 2026 |
| CVE-2026-86551 | LOW | 3.3 | The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factory_mac_address in the Settings.Secure … | Sep 20, 2026 |
| CVE-2026-94057 | MEDIUM | 4.0 | Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after … | Sep 19, 2026 |
| CVE-2026-94056 | HIGH | 7.5 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory. | Sep 19, 2026 |
| CVE-2026-94055 | LOW | 3.7 | Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free. | Sep 19, 2026 |
| CVE-2026-94054 | HIGH | 7.0 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. | Sep 19, 2026 |
| CVE-2026-93993 | HIGH | 8.8 | Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply … | Sep 19, 2026 |
| CVE-2026-93992 | HIGH | 8.1 | Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft … | Sep 19, 2026 |
| CVE-2026-93991 | HIGH | 7.7 | Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector … | Sep 19, 2026 |
| CVE-2026-93990 | HIGH | 7.5 | Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 … | Sep 19, 2026 |
| CVE-2026-93989 | LOW | 3.1 | vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). Attackers can supply out-of-bounds token indices that … | Sep 19, 2026 |
| CVE-2026-93988 | MEDIUM | 6.5 | QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can … | Sep 19, 2026 |
| CVE-2026-93956 | LOW | 3.5 | A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::buildHighlights of the file src/SearchEngine.php of the … | Sep 19, 2026 |
| CVE-2026-93955 | MEDIUM | 4.3 | A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the function streamFileToResponse of the file backend/src/main/java/org/booklore/controller/KoboController.java of the component … | Sep 19, 2026 |
| CVE-2026-89155 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 19, 2026 |
| CVE-2026-93954 | MEDIUM | 4.3 | A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of the component Settings … | Sep 19, 2026 |
| CVE-2026-82672 | UNKNOWN | — | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint … | Sep 19, 2026 |
| CVE-2026-82560 | UNKNOWN | — | Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width. … | Sep 19, 2026 |
| CVE-2026-94001 | MEDIUM | 6.5 | A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user credentials … | Sep 19, 2026 |
| CVE-2026-94000 | MEDIUM | 6.6 | A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints … | Sep 19, 2026 |
| CVE-2026-93999 | MEDIUM | 4.2 | A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token refresh … | Sep 19, 2026 |
| CVE-2026-93987 | LOW | 3.4 | rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin. newVolume() in cmd/serve/docker/volume.go computes a volume's mountpoint as … | Sep 19, 2026 |
| CVE-2026-93986 | LOW | 3.1 | rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers … | Sep 19, 2026 |
| CVE-2026-93985 | CRITICAL | 9.9 | OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor … | Sep 19, 2026 |