Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56172
Total
4442
Critical
16641
High
16421
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-81321 | CRITICAL | 9.8 | CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker who obtains filesystem access through physical access, a debugging … | Sep 18, 2026 |
| CVE-2026-77616 | MEDIUM | 6.1 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. In versions 7.0.0 through 7.1.0, … | Sep 18, 2026 |
| CVE-2026-77610 | MEDIUM | 6.1 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, query … | Sep 18, 2026 |
| CVE-2026-77609 | MEDIUM | 6.1 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `Special:URIResolver` … | Sep 18, 2026 |
| CVE-2026-77608 | MEDIUM | 6.1 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when … | Sep 18, 2026 |
| CVE-2026-77607 | MEDIUM | 6.1 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `sep` … | Sep 18, 2026 |
| CVE-2026-77606 | MEDIUM | 6.1 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when … | Sep 18, 2026 |
| CVE-2026-77339 | UNKNOWN | — | Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listener in src/mcp/server.go accepts browser-origin requests to /sse and … | Sep 18, 2026 |
| CVE-2026-77301 | HIGH | 7.5 | adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEntry.js trusts an entry's central-directory uncompressed size … | Sep 18, 2026 |
| CVE-2026-77240 | CRITICAL | 9.9 | WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-level security policy in supabase/migrations/017_account_sharing.sql permits authenticated users to modify … | Sep 18, 2026 |
| CVE-2026-77239 | HIGH | 8.1 | WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, WACRM flow and automation write routes authenticate account viewers but do not … | Sep 18, 2026 |
| CVE-2026-73863 | UNKNOWN | — | NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side MQTT v5 nmq_subinfo_decode() function in nng/src/sp/protocol/mqtt/mqtt_parser.c reuses len_of_varint from the outer Properties Length while parsing … | Sep 18, 2026 |
| CVE-2026-63406 | MEDIUM | 5.9 | AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemetry subsystem in telemetry/config.go enables tracking with a … | Sep 18, 2026 |
| CVE-2026-63405 | MEDIUM | 5.9 | AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the Pusher-compatible REST API in pusher/http.go includes the caller-supplied … | Sep 18, 2026 |
| CVE-2026-63349 | UNKNOWN | — | AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX … | Sep 18, 2026 |
| CVE-2026-62943 | UNKNOWN | — | btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_filter_btrbk.sh constructs allow_stream_match with a start anchor … | Sep 18, 2026 |
| CVE-2026-61833 | HIGH | 8.1 | zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior to 2.1.18, the bearer authentication handler in pkg/api/authn.go … | Sep 18, 2026 |
| CVE-2026-61795 | MEDIUM | 6.8 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, hostnameRegexHandler.OnUpdate in internal/webhook/tenant/validation/hostname_regex.go reverses the new and old Tenant parameters and validates … | Sep 18, 2026 |
| CVE-2026-61794 | MEDIUM | 6.8 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update validation in internal/webhook/tenant/validation/forbidden_annotations_regex.go compiles ForbiddenLabels.Regex for both the labels … | Sep 18, 2026 |
| CVE-2026-61672 | HIGH | 7.1 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in pkg/api/forbidden_list.go sorts denied metadata keys case-insensitively and then uses sort.SearchStrings, which … | Sep 18, 2026 |
| CVE-2026-61633 | LOW | 2.0 | NanoMQ is an MQTT broker. Prior to 0.24.14, the NanoMQ client function nni_mqtt_msg_decode_unsubscribe() in nng/src/supplemental/mqtt/mqtt_codec.c does not handle a failed read_uint16() while counting topics in … | Sep 18, 2026 |
| CVE-2026-61548 | HIGH | 8.1 | Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseSD_PARAM function in plugins/mmpstrucdata/mmpstrucdata.c stores RFC5424 parameter values in … | Sep 18, 2026 |
| CVE-2026-58197 | HIGH | 8.8 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to ToolHive CLI 0.30.1 and ToolHive Studio 0.38.0, … | Sep 18, 2026 |
| CVE-2026-55556 | UNKNOWN | — | Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_auth_header function in contrib/imhttp/imhttp.c allocates a zero-byte heap buffer … | Sep 18, 2026 |
| CVE-2026-46655 | HIGH | 7.8 | virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT … | Sep 18, 2026 |