Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56334
Total
4455
Critical
16700
High
16518
Medium
CVE ID Severity Score Description Published
CVE-2026-79294 MEDIUM 6.1 Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML artifact Preview … Sep 18, 2026
CVE-2026-62282 MEDIUM 6.5 OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack integrations does not sufficiently validate user-supplied HTTP or HTTPS … Sep 18, 2026
CVE-2023-5778 HIGH 7.5 Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900. … Sep 18, 2026
CVE-2026-93492 MEDIUM 5.3 A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. This … Sep 18, 2026
CVE-2026-93491 HIGH 7.5 A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding … Sep 18, 2026
CVE-2026-93488 HIGH 7.5 A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no … Sep 18, 2026
CVE-2026-28199 LOW 3.3 An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially … Sep 18, 2026
CVE-2026-28198 HIGH 8.8 An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command … Sep 18, 2026
CVE-2026-28197 HIGH 8.8 An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing … Sep 18, 2026
CVE-2026-21806 LOW 3.1 HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative account, which … Sep 18, 2026
CVE-2026-93578 MEDIUM 5.9 A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP … Sep 18, 2026
CVE-2026-93575 HIGH 7.5 A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. The decoder … Sep 18, 2026
CVE-2026-93572 HIGH 7.5 A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially crafted nested Redis (RESP) array headers. This … Sep 18, 2026
CVE-2026-93563 HIGH 7.5 A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP server, could exploit this by sending … Sep 18, 2026
CVE-2026-93561 MEDIUM 6.5 A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified … Sep 18, 2026
CVE-2026-81627 MEDIUM 6.7 A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM … Sep 18, 2026
CVE-2026-92976 UNKNOWN — A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite. An authenticated user could inject malicious HTML or JavaScript … Sep 18, 2026
CVE-2026-90884 MEDIUM 5.4 The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all versions up to, and including, 10.8.1 … Sep 18, 2026
CVE-2026-87915 HIGH 7.2 The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … Sep 18, 2026
CVE-2026-87743 HIGH 7.5 A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the security matcher and … Sep 18, 2026
CVE-2026-18405 HIGH 7.2 The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … Sep 18, 2026
CVE-2026-15797 MEDIUM 6.4 The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … Sep 18, 2026
CVE-2026-15579 UNKNOWN — An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the username field length during Web login processing. This … Sep 18, 2026
CVE-2026-85410 HIGH 8.1 The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to … Sep 18, 2026
CVE-2026-83561 HIGH 7.2 The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Elementor Cookie Blocker Regex in all … Sep 18, 2026