Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56102
Total
4437
Critical
16640
High
16418
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-75878 | CRITICAL | 9.1 | IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated … | Sep 18, 2026 |
| CVE-2026-63647 | UNKNOWN | — | CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close … | Sep 18, 2026 |
| CVE-2026-63646 | UNKNOWN | — | CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, GET /mcp/form/config/{formKey} calls McpController.getMcpField without authentication because ShiroFilter.addPublicPathFilters … | Sep 18, 2026 |
| CVE-2026-61822 | MEDIUM | 6.5 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance() handles exceptions outside the loop that processes rows … | Sep 18, 2026 |
| CVE-2026-61821 | HIGH | 8.5 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, drop_partition_id() and drop_partition_time() use part_config.retention_schema as the target for … | Sep 18, 2026 |
| CVE-2026-61820 | HIGH | 8.5 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, inherit_template_properties() manually surrounds primary-key column names from pg_attribute.attname with … | Sep 18, 2026 |
| CVE-2026-61819 | HIGH | 8.5 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pg_jobmon is installed and part_config.jobmon is true, exception … | Sep 18, 2026 |
| CVE-2026-61818 | HIGH | 8.5 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, undo_partition() reads part_config.time_encoder as unrestricted text and interpolates it … | Sep 18, 2026 |
| CVE-2026-61817 | HIGH | 8.5 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance(), show_partitions(), show_partition_info(), undo_partition(), and partition_data_time() interpolate the writable … | Sep 18, 2026 |
| CVE-2026-61781 | CRITICAL | 9.9 | pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates … | Sep 18, 2026 |
| CVE-2026-61723 | MEDIUM | 6.8 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates ptbl chunks with the unsigned … | Sep 18, 2026 |
| CVE-2026-61722 | MEDIUM | 6.8 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates articulation chunks using the unsigned … | Sep 18, 2026 |
| CVE-2026-61721 | HIGH | 8.0 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values … | Sep 18, 2026 |
| CVE-2026-61720 | MEDIUM | 6.2 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the SF2 parser computes the DMOD modulator count as chunk.size … | Sep 18, 2026 |
| CVE-2026-61714 | HIGH | 7.8 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index … | Sep 18, 2026 |
| CVE-2026-58264 | CRITICAL | 9.8 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel … | Sep 18, 2026 |
| CVE-2026-57226 | LOW | 3.7 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, HTTP SWF decompression with the … | Sep 18, 2026 |
| CVE-2026-57224 | MEDIUM | 6.5 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the DHCP parser in rust/src/dhcp/dhcp.rs creates … | Sep 18, 2026 |
| CVE-2026-57222 | MEDIUM | 5.3 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, crafted IPv4 and IPv6 address … | Sep 18, 2026 |
| CVE-2026-52745 | MEDIUM | 5.3 | CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.0, the POST /account-pool/page endpoint allows an authenticated caller … | Sep 18, 2026 |
| CVE-2026-18869 | MEDIUM | 6.4 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper … | Sep 18, 2026 |
| CVE-2026-17619 | HIGH | 8.6 | IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, … | Sep 18, 2026 |
| CVE-2026-17262 | MEDIUM | 5.4 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication … | Sep 18, 2026 |
| CVE-2026-11727 | HIGH | 8.1 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially … | Sep 18, 2026 |
| CVE-2026-11726 | HIGH | 8.1 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to … | Sep 18, 2026 |