Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56172
Total
4442
Critical
16641
High
16421
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-77929 | HIGH | 8.8 | ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid … | Sep 18, 2026 |
| CVE-2026-77928 | MEDIUM | 6.5 | ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary database contents by submitting the msg_id parameter as … | Sep 18, 2026 |
| CVE-2026-77927 | MEDIUM | 6.5 | ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary data from the database by submitting the check_photo … | Sep 18, 2026 |
| CVE-2026-25684 | MEDIUM | 4.4 | A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare … | Sep 18, 2026 |
| CVE-2026-16515 | MEDIUM | 4.7 | net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one of the three RFC 4443 section 2.4 suppression rules (do not answer an ICMPv6 error with an ICMPv6 error). … | Sep 18, 2026 |
| CVE-2026-16514 | MEDIUM | 4.3 | gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS Announce message, comparing each clock identity against the local one. The loop … | Sep 18, 2026 |
| CVE-2026-16512 | LOW | 3.1 | gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched on hdr->message_type without first checking that the received frame carries at least sizeof(struct … | Sep 18, 2026 |
| CVE-2026-10832 | MEDIUM | 5.9 | A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability by sending a specially crafted DER … | Sep 18, 2026 |
| CVE-2025-1350 | MEDIUM | 5.3 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitive information when a detailed technical error … | Sep 18, 2026 |
| CVE-2025-13882 | MEDIUM | 5.3 | IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 … | Sep 18, 2026 |
| CVE-2024-56344 | MEDIUM | 5.9 | IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure … | Sep 18, 2026 |
| CVE-2026-93606 | CRITICAL | 10.0 | vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm … | Sep 18, 2026 |
| CVE-2026-93605 | CRITICAL | 10.0 | vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process … | Sep 18, 2026 |
| CVE-2026-93604 | HIGH | 7.2 | vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allowlists the crypto builtin for a NodeVM (require.builtin: ['crypto']). The … | Sep 18, 2026 |
| CVE-2026-93603 | CRITICAL | 10.0 | vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code … | Sep 18, 2026 |
| CVE-2026-93602 | MEDIUM | 4.4 | rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints. Attackers … | Sep 18, 2026 |
| CVE-2026-93601 | LOW | 2.2 | rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates … | Sep 18, 2026 |
| CVE-2026-93600 | LOW | 2.2 | rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be … | Sep 18, 2026 |
| CVE-2026-93599 | HIGH | 7.5 | rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT … | Sep 18, 2026 |
| CVE-2026-93598 | UNKNOWN | — | ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script sandbox: com.arcadedb.query.polyglot.HostClassLookupFilter.DENIED lists java.util.ResourceBundle as a bare class name, which is … | Sep 18, 2026 |
| CVE-2026-93597 | HIGH | 7.7 | ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply … | Sep 18, 2026 |
| CVE-2026-93596 | MEDIUM | 4.3 | ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the DatabaseAsyncTransaction async worker threads used by the parallel edge-connect phase of … | Sep 18, 2026 |
| CVE-2026-93595 | MEDIUM | 6.5 | ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool exposed through the AI chat endpoints. The tool executes queries without binding … | Sep 18, 2026 |
| CVE-2026-93594 | HIGH | 8.1 | ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id. Query-execution paths that reach record data through … | Sep 18, 2026 |
| CVE-2026-93593 | HIGH | 8.1 | ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but TimeSeries types … | Sep 18, 2026 |