Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56172
Total
4442
Critical
16641
High
16421
Medium
CVE ID Severity Score Description Published
CVE-2026-93750 MEDIUM 5.9 http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. … Sep 18, 2026
CVE-2026-93749 HIGH 7.5 source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply … Sep 18, 2026
CVE-2026-93748 HIGH 7.5 http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other … Sep 18, 2026
CVE-2026-93432 MEDIUM 6.1 A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's … Sep 18, 2026
CVE-2026-92768 MEDIUM 5.5 A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process … Sep 18, 2026
CVE-2026-92747 MEDIUM 5.0 A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine … Sep 18, 2026
CVE-2026-92745 MEDIUM 5.0 A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat … Sep 18, 2026
CVE-2026-92702 CRITICAL 9.1 Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested … Sep 18, 2026
CVE-2026-92701 CRITICAL 9.1 trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session … Sep 18, 2026
CVE-2026-91127 HIGH 8.2 File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and … Sep 18, 2026
CVE-2026-85058 HIGH 7.5 Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used … Sep 18, 2026
CVE-2026-84992 MEDIUM 6.1 md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt() highlight callback in packages/MdEditor/layouts/Content/composition/useMarkdownIt.ts inserts a fenced-code … Sep 18, 2026
CVE-2026-84975 HIGH 7.4 PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuTLS backends in pjlib/src/pj/ssl_sock_ossl.c and … Sep 18, 2026
CVE-2026-81182 MEDIUM 4.2 SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a public read-write note share link can disclose an … Sep 18, 2026
CVE-2026-81181 LOW 3.7 SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier … Sep 18, 2026
CVE-2026-81180 HIGH 8.8 SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing … Sep 18, 2026
CVE-2026-81179 HIGH 8.1 SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept … Sep 18, 2026
CVE-2026-81178 LOW 3.5 SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public note share link receives project-wide collaborative editing metadata … Sep 18, 2026
CVE-2026-77396 UNKNOWN — PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser in pjmedia/src/pjmedia/avi_player.c uses an … Sep 18, 2026
CVE-2026-77386 MEDIUM 6.5 Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker could initiate the OIDC login flow with … Sep 18, 2026
CVE-2026-77385 MEDIUM 4.3 Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a … Sep 18, 2026
CVE-2026-71537 MEDIUM 6.5 Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7, app/Livewire/Services/Upgrade.php::doUpgrade() relies on Service::upgradable to check for a pending … Sep 18, 2026
CVE-2026-69186 MEDIUM 5.3 c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains … Sep 18, 2026
CVE-2026-69184 HIGH 7.5 c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled … Sep 18, 2026
CVE-2026-64847 UNKNOWN — AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, AnyIO starts process-pool … Sep 18, 2026