Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56172
Total
4442
Critical
16641
High
16421
Medium
CVE ID Severity Score Description Published
CVE-2026-81944 HIGH 7.5 PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds … Sep 18, 2026
CVE-2026-81943 MEDIUM 6.7 PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain active debug functionality in the embedded software. An attacker with … Sep 18, 2026
CVE-2026-81942 HIGH 8.8 PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain an OS command injection vulnerability in the web server. User-supplied … Sep 18, 2026
CVE-2026-81305 MEDIUM 6.8 CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device … Sep 18, 2026
CVE-2026-7006 HIGH 7.3 Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege escalation vulnerability that allows unprivileged … Sep 18, 2026
CVE-2026-77960 MEDIUM 5.3 Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers … Sep 18, 2026
CVE-2026-77568 MEDIUM 4.2 Mojolicious is a real-time web framework for Perl. Prior to 9.48, the Mojolicious CSRF helpers csrf_field, csrf_token, and csrf_protect reuse an unchanged per-session token in … Sep 18, 2026
CVE-2026-75883 MEDIUM 6.8 The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes … Sep 18, 2026
CVE-2026-75031 CRITICAL 9.8 In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code … Sep 18, 2026
CVE-2026-68914 UNKNOWN — Mojolicious is a real-time web framework for Perl. Prior to 9.47, the pure-Perl implementation of Mojo::JSON does not limit nesting depth when Cpanel::JSON::XS is unavailable … Sep 18, 2026
CVE-2026-67549 HIGH 7.6 OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, A … Sep 18, 2026
CVE-2026-65970 MEDIUM 5.3 OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, a … Sep 18, 2026
CVE-2026-65969 MEDIUM 5.5 OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, … Sep 18, 2026
CVE-2026-63638 HIGH 8.3 OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, … Sep 18, 2026
CVE-2026-63635 MEDIUM 5.5 OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, … Sep 18, 2026
CVE-2026-63422 HIGH 7.8 OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, … Sep 18, 2026
CVE-2026-63420 MEDIUM 5.5 OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, … Sep 18, 2026
CVE-2026-63419 HIGH 7.8 OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, … Sep 18, 2026
CVE-2026-61682 CRITICAL 9.9 kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not … Sep 18, 2026
CVE-2026-60115 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Sep 18, 2026
CVE-2026-59956 MEDIUM 6.1 OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, … Sep 18, 2026
CVE-2026-59181 MEDIUM 6.1 OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, … Sep 18, 2026
CVE-2026-59156 MEDIUM 6.5 OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, … Sep 18, 2026
CVE-2026-54148 HIGH 8.1 http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in … Sep 18, 2026
CVE-2026-54147 MEDIUM 6.5 http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest ignores its configured algorithm parameter and verifies … Sep 18, 2026