Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56102
Total
4437
Critical
16640
High
16418
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-63451 | LOW | 3.3 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, a locally supplied detection rule that … | Sep 18, 2026 |
| CVE-2026-63450 | LOW | 3.7 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 8.0.6, the FTP parser in src/app-layer-ftp.c treats a … | Sep 18, 2026 |
| CVE-2026-63449 | LOW | 3.7 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SIP parser in rust/src/sip/parser.rs stores … | Sep 18, 2026 |
| CVE-2026-63448 | MEDIUM | 5.9 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the SMB parser can retain … | Sep 18, 2026 |
| CVE-2026-63447 | HIGH | 7.5 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can … | Sep 18, 2026 |
| CVE-2026-63446 | HIGH | 7.5 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted … | Sep 18, 2026 |
| CVE-2026-61670 | MEDIUM | 6.5 | microsandbox is an easy, fast, local-first microVM runtime and library. Prior to 0.5.10, sdk/rust/lib/runtime/spawn.rs serializes NetworkConfig secret values into the --network-config argument and passes per-sandbox … | Sep 18, 2026 |
| CVE-2026-57229 | MEDIUM | 5.3 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SMTP MIME parser in rust/src/mime/smtp.rs … | Sep 18, 2026 |
| CVE-2026-57228 | HIGH | 8.2 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in … | Sep 18, 2026 |
| CVE-2026-57227 | HIGH | 7.5 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in … | Sep 18, 2026 |
| CVE-2026-57225 | LOW | 3.3 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, src/datasets-context-json.c assumes that a configured JSON … | Sep 18, 2026 |
| CVE-2026-57223 | HIGH | 7.0 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the Windows service installation and … | Sep 18, 2026 |
| CVE-2026-93873 | MEDIUM | 4.3 | Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages. Attackers can auto-submit contact forms from … | Sep 18, 2026 |
| CVE-2026-93872 | HIGH | 7.5 | Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate … | Sep 18, 2026 |
| CVE-2026-93871 | MEDIUM | 5.4 | Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store … | Sep 18, 2026 |
| CVE-2026-93870 | MEDIUM | 4.3 | Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge ratings on behalf of authenticated users. Attackers … | Sep 18, 2026 |
| CVE-2026-93869 | MEDIUM | 6.1 | Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor. Attackers … | Sep 18, 2026 |
| CVE-2026-93868 | HIGH | 8.1 | Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated … | Sep 18, 2026 |
| CVE-2026-93841 | LOW | 3.7 | vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset without bounds checking against … | Sep 18, 2026 |
| CVE-2026-93840 | LOW | 3.7 | vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids(). Attackers can supply token IDs above the output vocabulary … | Sep 18, 2026 |
| CVE-2026-93839 | CRITICAL | 9.8 | LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON … | Sep 18, 2026 |
| CVE-2026-93838 | MEDIUM | 5.9 | SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments. … | Sep 18, 2026 |
| CVE-2026-93031 | HIGH | 8.8 | The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, … | Sep 18, 2026 |
| CVE-2026-92708 | HIGH | 7.5 | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and … | Sep 18, 2026 |
| CVE-2026-91205 | MEDIUM | 6.0 | A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation with owner assignment. By controlling a writable … | Sep 18, 2026 |