Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56102
Total
4437
Critical
16640
High
16418
Medium
CVE ID Severity Score Description Published
CVE-2026-75878 CRITICAL 9.1 IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated … Sep 18, 2026
CVE-2026-63647 UNKNOWN — CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close … Sep 18, 2026
CVE-2026-63646 UNKNOWN — CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, GET /mcp/form/config/{formKey} calls McpController.getMcpField without authentication because ShiroFilter.addPublicPathFilters … Sep 18, 2026
CVE-2026-61822 MEDIUM 6.5 pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance() handles exceptions outside the loop that processes rows … Sep 18, 2026
CVE-2026-61821 HIGH 8.5 pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, drop_partition_id() and drop_partition_time() use part_config.retention_schema as the target for … Sep 18, 2026
CVE-2026-61820 HIGH 8.5 pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, inherit_template_properties() manually surrounds primary-key column names from pg_attribute.attname with … Sep 18, 2026
CVE-2026-61819 HIGH 8.5 pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pg_jobmon is installed and part_config.jobmon is true, exception … Sep 18, 2026
CVE-2026-61818 HIGH 8.5 pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, undo_partition() reads part_config.time_encoder as unrestricted text and interpolates it … Sep 18, 2026
CVE-2026-61817 HIGH 8.5 pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance(), show_partitions(), show_partition_info(), undo_partition(), and partition_data_time() interpolate the writable … Sep 18, 2026
CVE-2026-61781 CRITICAL 9.9 pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates … Sep 18, 2026
CVE-2026-61723 MEDIUM 6.8 FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates ptbl chunks with the unsigned … Sep 18, 2026
CVE-2026-61722 MEDIUM 6.8 FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates articulation chunks using the unsigned … Sep 18, 2026
CVE-2026-61721 HIGH 8.0 FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values … Sep 18, 2026
CVE-2026-61720 MEDIUM 6.2 FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the SF2 parser computes the DMOD modulator count as chunk.size … Sep 18, 2026
CVE-2026-61714 HIGH 7.8 FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index … Sep 18, 2026
CVE-2026-58264 CRITICAL 9.8 FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel … Sep 18, 2026
CVE-2026-57226 LOW 3.7 Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, HTTP SWF decompression with the … Sep 18, 2026
CVE-2026-57224 MEDIUM 6.5 Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the DHCP parser in rust/src/dhcp/dhcp.rs creates … Sep 18, 2026
CVE-2026-57222 MEDIUM 5.3 Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, crafted IPv4 and IPv6 address … Sep 18, 2026
CVE-2026-52745 MEDIUM 5.3 CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.0, the POST /account-pool/page endpoint allows an authenticated caller … Sep 18, 2026
CVE-2026-18869 MEDIUM 6.4 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper … Sep 18, 2026
CVE-2026-17619 HIGH 8.6 IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, … Sep 18, 2026
CVE-2026-17262 MEDIUM 5.4 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication … Sep 18, 2026
CVE-2026-11727 HIGH 8.1 IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially … Sep 18, 2026
CVE-2026-11726 HIGH 8.1 IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to … Sep 18, 2026