Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56102
Total
4437
Critical
16640
High
16418
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-93760 | HIGH | 8.2 | Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an … | Sep 18, 2026 |
| CVE-2026-93759 | HIGH | 8.6 | Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. … | Sep 18, 2026 |
| CVE-2026-93753 | HIGH | 7.5 | deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can … | Sep 18, 2026 |
| CVE-2026-93752 | HIGH | 7.5 | CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a … | Sep 18, 2026 |
| CVE-2026-93751 | MEDIUM | 6.5 | uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded … | Sep 18, 2026 |
| CVE-2026-93750 | MEDIUM | 5.9 | http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. … | Sep 18, 2026 |
| CVE-2026-93749 | HIGH | 7.5 | source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply … | Sep 18, 2026 |
| CVE-2026-93748 | HIGH | 7.5 | http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other … | Sep 18, 2026 |
| CVE-2026-93432 | MEDIUM | 6.1 | A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's … | Sep 18, 2026 |
| CVE-2026-92768 | MEDIUM | 5.5 | A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process … | Sep 18, 2026 |
| CVE-2026-92747 | MEDIUM | 5.0 | A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine … | Sep 18, 2026 |
| CVE-2026-92745 | MEDIUM | 5.0 | A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat … | Sep 18, 2026 |
| CVE-2026-92702 | CRITICAL | 9.1 | Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested … | Sep 18, 2026 |
| CVE-2026-92701 | CRITICAL | 9.1 | trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session … | Sep 18, 2026 |
| CVE-2026-91127 | HIGH | 8.2 | File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and … | Sep 18, 2026 |
| CVE-2026-85058 | HIGH | 7.5 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used … | Sep 18, 2026 |
| CVE-2026-84992 | MEDIUM | 6.1 | md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt() highlight callback in packages/MdEditor/layouts/Content/composition/useMarkdownIt.ts inserts a fenced-code … | Sep 18, 2026 |
| CVE-2026-84975 | HIGH | 7.4 | PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuTLS backends in pjlib/src/pj/ssl_sock_ossl.c and … | Sep 18, 2026 |
| CVE-2026-81182 | MEDIUM | 4.2 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a public read-write note share link can disclose an … | Sep 18, 2026 |
| CVE-2026-81181 | LOW | 3.7 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier … | Sep 18, 2026 |
| CVE-2026-81180 | HIGH | 8.8 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing … | Sep 18, 2026 |
| CVE-2026-81179 | HIGH | 8.1 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept … | Sep 18, 2026 |
| CVE-2026-81178 | LOW | 3.5 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public note share link receives project-wide collaborative editing metadata … | Sep 18, 2026 |
| CVE-2026-77396 | UNKNOWN | — | PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser in pjmedia/src/pjmedia/avi_player.c uses an … | Sep 18, 2026 |
| CVE-2026-77386 | MEDIUM | 6.5 | Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker could initiate the OIDC login flow with … | Sep 18, 2026 |