Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56334
Total
4455
Critical
16700
High
16518
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-93604 | HIGH | 7.2 | vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allowlists the crypto builtin for a NodeVM (require.builtin: ['crypto']). The … | Sep 18, 2026 |
| CVE-2026-93603 | CRITICAL | 10.0 | vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code … | Sep 18, 2026 |
| CVE-2026-93602 | MEDIUM | 4.4 | rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints. Attackers … | Sep 18, 2026 |
| CVE-2026-93601 | LOW | 2.2 | rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates … | Sep 18, 2026 |
| CVE-2026-93600 | LOW | 2.2 | rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be … | Sep 18, 2026 |
| CVE-2026-93599 | HIGH | 7.5 | rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT … | Sep 18, 2026 |
| CVE-2026-93598 | UNKNOWN | — | ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script sandbox: com.arcadedb.query.polyglot.HostClassLookupFilter.DENIED lists java.util.ResourceBundle as a bare class name, which is … | Sep 18, 2026 |
| CVE-2026-93597 | HIGH | 7.7 | ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply … | Sep 18, 2026 |
| CVE-2026-93596 | MEDIUM | 4.3 | ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the DatabaseAsyncTransaction async worker threads used by the parallel edge-connect phase of … | Sep 18, 2026 |
| CVE-2026-93595 | MEDIUM | 6.5 | ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool exposed through the AI chat endpoints. The tool executes queries without binding … | Sep 18, 2026 |
| CVE-2026-93594 | HIGH | 8.1 | ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id. Query-execution paths that reach record data through … | Sep 18, 2026 |
| CVE-2026-93593 | HIGH | 8.1 | ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but TimeSeries types … | Sep 18, 2026 |
| CVE-2026-93592 | HIGH | 7.5 | vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the … | Sep 18, 2026 |
| CVE-2026-93591 | HIGH | 7.6 | SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without … | Sep 18, 2026 |
| CVE-2026-93590 | LOW | 3.7 | ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers … | Sep 18, 2026 |
| CVE-2026-93589 | LOW | 3.7 | ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded … | Sep 18, 2026 |
| CVE-2026-93588 | LOW | 3.1 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder reaches a memory (resource) limit at a … | Sep 18, 2026 |
| CVE-2026-93587 | LOW | 3.3 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific … | Sep 18, 2026 |
| CVE-2026-93586 | LOW | 2.9 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may … | Sep 18, 2026 |
| CVE-2026-93560 | HIGH | 7.5 | A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the … | Sep 18, 2026 |
| CVE-2026-93504 | MEDIUM | 6.3 | A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+server.ts of the component User Attribute Update Endpoint. Such … | Sep 18, 2026 |
| CVE-2026-93019 | CRITICAL | 9.1 | Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader … | Sep 18, 2026 |
| CVE-2026-93018 | UNKNOWN | — | Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. … | Sep 18, 2026 |
| CVE-2026-88623 | UNKNOWN | — | NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the user via POST is received, and … | Sep 18, 2026 |
| CVE-2026-88622 | HIGH | 8.8 | NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php. | Sep 18, 2026 |