Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56172
Total
4442
Critical
16641
High
16421
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-93572 | HIGH | 7.5 | A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially crafted nested Redis (RESP) array headers. This … | Sep 18, 2026 |
| CVE-2026-93563 | HIGH | 7.5 | A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP server, could exploit this by sending … | Sep 18, 2026 |
| CVE-2026-93561 | MEDIUM | 6.5 | A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified … | Sep 18, 2026 |
| CVE-2026-81627 | MEDIUM | 6.7 | A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM … | Sep 18, 2026 |
| CVE-2026-92976 | UNKNOWN | — | A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite. An authenticated user could inject malicious HTML or JavaScript … | Sep 18, 2026 |
| CVE-2026-90884 | MEDIUM | 5.4 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all versions up to, and including, 10.8.1 … | Sep 18, 2026 |
| CVE-2026-87915 | HIGH | 7.2 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | Sep 18, 2026 |
| CVE-2026-87743 | HIGH | 7.5 | A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the security matcher and … | Sep 18, 2026 |
| CVE-2026-18405 | HIGH | 7.2 | The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | Sep 18, 2026 |
| CVE-2026-15797 | MEDIUM | 6.4 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | Sep 18, 2026 |
| CVE-2026-15579 | UNKNOWN | — | An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the username field length during Web login processing. This … | Sep 18, 2026 |
| CVE-2026-85410 | HIGH | 8.1 | The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to … | Sep 18, 2026 |
| CVE-2026-83561 | HIGH | 7.2 | The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Elementor Cookie Blocker Regex in all … | Sep 18, 2026 |
| CVE-2026-6205 | HIGH | 8.1 | An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote … | Sep 18, 2026 |
| CVE-2026-56597 | LOW | 3.1 | HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the … | Sep 18, 2026 |
| CVE-2026-56595 | LOW | 3.1 | HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin headers, which could allow an attacker to craft a … | Sep 18, 2026 |
| CVE-2026-56592 | MEDIUM | 6.5 | HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate account lockouts, which could allow an unauthenticated attacker to execute … | Sep 18, 2026 |
| CVE-2026-56590 | MEDIUM | 6.4 | HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation controls, which could allow an unauthenticated attacker to … | Sep 18, 2026 |
| CVE-2026-4036 | MEDIUM | 6.5 | An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 … | Sep 18, 2026 |
| CVE-2026-40539 | HIGH | 7.1 | An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write … | Sep 18, 2026 |
| CVE-2026-40538 | LOW | 3.7 | An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to … | Sep 18, 2026 |
| CVE-2026-40537 | MEDIUM | 4.3 | A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain … | Sep 18, 2026 |
| CVE-2026-40536 | MEDIUM | 4.3 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and … | Sep 18, 2026 |
| CVE-2026-40535 | MEDIUM | 6.5 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and … | Sep 18, 2026 |
| CVE-2026-40534 | MEDIUM | 5.4 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 … | Sep 18, 2026 |