Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56172
Total
4442
Critical
16641
High
16421
Medium
CVE ID Severity Score Description Published
CVE-2026-93592 HIGH 7.5 vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the … Sep 18, 2026
CVE-2026-93591 HIGH 7.6 SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without … Sep 18, 2026
CVE-2026-93590 LOW 3.7 ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers … Sep 18, 2026
CVE-2026-93589 LOW 3.7 ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded … Sep 18, 2026
CVE-2026-93588 LOW 3.1 ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder reaches a memory (resource) limit at a … Sep 18, 2026
CVE-2026-93587 LOW 3.3 ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific … Sep 18, 2026
CVE-2026-93586 LOW 2.9 ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may … Sep 18, 2026
CVE-2026-93560 HIGH 7.5 A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the … Sep 18, 2026
CVE-2026-93504 MEDIUM 6.3 A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+server.ts of the component User Attribute Update Endpoint. Such … Sep 18, 2026
CVE-2026-93019 CRITICAL 9.1 Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader … Sep 18, 2026
CVE-2026-93018 UNKNOWN — Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. … Sep 18, 2026
CVE-2026-88623 UNKNOWN — NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the user via POST is received, and … Sep 18, 2026
CVE-2026-88622 HIGH 8.8 NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php. Sep 18, 2026
CVE-2026-79294 MEDIUM 6.1 Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML artifact Preview … Sep 18, 2026
CVE-2026-62282 MEDIUM 6.5 OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack integrations does not sufficiently validate user-supplied HTTP or HTTPS … Sep 18, 2026
CVE-2023-5778 HIGH 7.5 Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900. … Sep 18, 2026
CVE-2026-93492 MEDIUM 5.3 A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. This … Sep 18, 2026
CVE-2026-93491 HIGH 7.5 A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding … Sep 18, 2026
CVE-2026-93488 HIGH 7.5 A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no … Sep 18, 2026
CVE-2026-28199 LOW 3.3 An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially … Sep 18, 2026
CVE-2026-28198 HIGH 8.8 An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command … Sep 18, 2026
CVE-2026-28197 HIGH 8.8 An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing … Sep 18, 2026
CVE-2026-21806 LOW 3.1 HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative account, which … Sep 18, 2026
CVE-2026-93578 MEDIUM 5.9 A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP … Sep 18, 2026
CVE-2026-93575 HIGH 7.5 A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. The decoder … Sep 18, 2026