Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56172
Total
4442
Critical
16641
High
16421
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-81944 | HIGH | 7.5 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds … | Sep 18, 2026 |
| CVE-2026-81943 | MEDIUM | 6.7 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain active debug functionality in the embedded software. An attacker with … | Sep 18, 2026 |
| CVE-2026-81942 | HIGH | 8.8 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain an OS command injection vulnerability in the web server. User-supplied … | Sep 18, 2026 |
| CVE-2026-81305 | MEDIUM | 6.8 | CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device … | Sep 18, 2026 |
| CVE-2026-7006 | HIGH | 7.3 | Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege escalation vulnerability that allows unprivileged … | Sep 18, 2026 |
| CVE-2026-77960 | MEDIUM | 5.3 | Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers … | Sep 18, 2026 |
| CVE-2026-77568 | MEDIUM | 4.2 | Mojolicious is a real-time web framework for Perl. Prior to 9.48, the Mojolicious CSRF helpers csrf_field, csrf_token, and csrf_protect reuse an unchanged per-session token in … | Sep 18, 2026 |
| CVE-2026-75883 | MEDIUM | 6.8 | The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes … | Sep 18, 2026 |
| CVE-2026-75031 | CRITICAL | 9.8 | In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code … | Sep 18, 2026 |
| CVE-2026-68914 | UNKNOWN | — | Mojolicious is a real-time web framework for Perl. Prior to 9.47, the pure-Perl implementation of Mojo::JSON does not limit nesting depth when Cpanel::JSON::XS is unavailable … | Sep 18, 2026 |
| CVE-2026-67549 | HIGH | 7.6 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, A … | Sep 18, 2026 |
| CVE-2026-65970 | MEDIUM | 5.3 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, a … | Sep 18, 2026 |
| CVE-2026-65969 | MEDIUM | 5.5 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, … | Sep 18, 2026 |
| CVE-2026-63638 | HIGH | 8.3 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, … | Sep 18, 2026 |
| CVE-2026-63635 | MEDIUM | 5.5 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, … | Sep 18, 2026 |
| CVE-2026-63422 | HIGH | 7.8 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, … | Sep 18, 2026 |
| CVE-2026-63420 | MEDIUM | 5.5 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, … | Sep 18, 2026 |
| CVE-2026-63419 | HIGH | 7.8 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, … | Sep 18, 2026 |
| CVE-2026-61682 | CRITICAL | 9.9 | kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not … | Sep 18, 2026 |
| CVE-2026-60115 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 18, 2026 |
| CVE-2026-59956 | MEDIUM | 6.1 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, … | Sep 18, 2026 |
| CVE-2026-59181 | MEDIUM | 6.1 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, … | Sep 18, 2026 |
| CVE-2026-59156 | MEDIUM | 6.5 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, … | Sep 18, 2026 |
| CVE-2026-54148 | HIGH | 8.1 | http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in … | Sep 18, 2026 |
| CVE-2026-54147 | MEDIUM | 6.5 | http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest ignores its configured algorithm parameter and verifies … | Sep 18, 2026 |