Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56102
Total
4437
Critical
16640
High
16418
Medium
CVE ID Severity Score Description Published
CVE-2026-93760 HIGH 8.2 Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an … Sep 18, 2026
CVE-2026-93759 HIGH 8.6 Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. … Sep 18, 2026
CVE-2026-93753 HIGH 7.5 deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can … Sep 18, 2026
CVE-2026-93752 HIGH 7.5 CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a … Sep 18, 2026
CVE-2026-93751 MEDIUM 6.5 uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded … Sep 18, 2026
CVE-2026-93750 MEDIUM 5.9 http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. … Sep 18, 2026
CVE-2026-93749 HIGH 7.5 source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply … Sep 18, 2026
CVE-2026-93748 HIGH 7.5 http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other … Sep 18, 2026
CVE-2026-93432 MEDIUM 6.1 A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's … Sep 18, 2026
CVE-2026-92768 MEDIUM 5.5 A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process … Sep 18, 2026
CVE-2026-92747 MEDIUM 5.0 A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine … Sep 18, 2026
CVE-2026-92745 MEDIUM 5.0 A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat … Sep 18, 2026
CVE-2026-92702 CRITICAL 9.1 Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested … Sep 18, 2026
CVE-2026-92701 CRITICAL 9.1 trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session … Sep 18, 2026
CVE-2026-91127 HIGH 8.2 File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and … Sep 18, 2026
CVE-2026-85058 HIGH 7.5 Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used … Sep 18, 2026
CVE-2026-84992 MEDIUM 6.1 md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt() highlight callback in packages/MdEditor/layouts/Content/composition/useMarkdownIt.ts inserts a fenced-code … Sep 18, 2026
CVE-2026-84975 HIGH 7.4 PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuTLS backends in pjlib/src/pj/ssl_sock_ossl.c and … Sep 18, 2026
CVE-2026-81182 MEDIUM 4.2 SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a public read-write note share link can disclose an … Sep 18, 2026
CVE-2026-81181 LOW 3.7 SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier … Sep 18, 2026
CVE-2026-81180 HIGH 8.8 SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing … Sep 18, 2026
CVE-2026-81179 HIGH 8.1 SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept … Sep 18, 2026
CVE-2026-81178 LOW 3.5 SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public note share link receives project-wide collaborative editing metadata … Sep 18, 2026
CVE-2026-77396 UNKNOWN — PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser in pjmedia/src/pjmedia/avi_player.c uses an … Sep 18, 2026
CVE-2026-77386 MEDIUM 6.5 Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker could initiate the OIDC login flow with … Sep 18, 2026