Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56334
Total
4455
Critical
16700
High
16518
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-93576 | HIGH | 7.5 | A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP command-name … | Sep 18, 2026 |
| CVE-2026-93573 | MEDIUM | 6.5 | A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across … | Sep 18, 2026 |
| CVE-2026-93569 | HIGH | 8.2 | A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request … | Sep 18, 2026 |
| CVE-2026-93568 | HIGH | 7.5 | A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. Netty's HTTP-object … | Sep 18, 2026 |
| CVE-2026-93567 | HIGH | 7.5 | A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the … | Sep 18, 2026 |
| CVE-2026-93566 | MEDIUM | 6.5 | A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the … | Sep 18, 2026 |
| CVE-2026-93565 | HIGH | 7.5 | A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens in Real-Time Streaming Protocol (RTSP) requests. A … | Sep 18, 2026 |
| CVE-2026-93564 | HIGH | 7.5 | A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to send specially crafted PROXY-protocol … | Sep 18, 2026 |
| CVE-2026-93558 | HIGH | 7.5 | A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the … | Sep 18, 2026 |
| CVE-2026-93506 | MEDIUM | 6.3 | A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/upload-media of the component File Upload Endpoint. Executing a … | Sep 18, 2026 |
| CVE-2026-93505 | LOW | 3.5 | A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-service.server.ts of the component SVG Media Upload. Performing a manipulation … | Sep 18, 2026 |
| CVE-2026-85511 | MEDIUM | 4.2 | A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution … | Sep 18, 2026 |
| CVE-2026-77929 | HIGH | 8.8 | ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid … | Sep 18, 2026 |
| CVE-2026-77928 | MEDIUM | 6.5 | ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary database contents by submitting the msg_id parameter as … | Sep 18, 2026 |
| CVE-2026-77927 | MEDIUM | 6.5 | ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary data from the database by submitting the check_photo … | Sep 18, 2026 |
| CVE-2026-25684 | MEDIUM | 4.4 | A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare … | Sep 18, 2026 |
| CVE-2026-16515 | MEDIUM | 4.7 | net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one of the three RFC 4443 section 2.4 suppression rules (do not answer an ICMPv6 error with an ICMPv6 error). … | Sep 18, 2026 |
| CVE-2026-16514 | MEDIUM | 4.3 | gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS Announce message, comparing each clock identity against the local one. The loop … | Sep 18, 2026 |
| CVE-2026-16512 | LOW | 3.1 | gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched on hdr->message_type without first checking that the received frame carries at least sizeof(struct … | Sep 18, 2026 |
| CVE-2026-10832 | MEDIUM | 5.9 | A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability by sending a specially crafted DER … | Sep 18, 2026 |
| CVE-2025-1350 | MEDIUM | 5.3 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitive information when a detailed technical error … | Sep 18, 2026 |
| CVE-2025-13882 | MEDIUM | 5.3 | IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 … | Sep 18, 2026 |
| CVE-2024-56344 | MEDIUM | 5.9 | IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure … | Sep 18, 2026 |
| CVE-2026-93606 | CRITICAL | 10.0 | vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm … | Sep 18, 2026 |
| CVE-2026-93605 | CRITICAL | 10.0 | vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process … | Sep 18, 2026 |