Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56334
Total
4455
Critical
16700
High
16518
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-79294 | MEDIUM | 6.1 | Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML artifact Preview … | Sep 18, 2026 |
| CVE-2026-62282 | MEDIUM | 6.5 | OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack integrations does not sufficiently validate user-supplied HTTP or HTTPS … | Sep 18, 2026 |
| CVE-2023-5778 | HIGH | 7.5 | Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900. … | Sep 18, 2026 |
| CVE-2026-93492 | MEDIUM | 5.3 | A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. This … | Sep 18, 2026 |
| CVE-2026-93491 | HIGH | 7.5 | A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding … | Sep 18, 2026 |
| CVE-2026-93488 | HIGH | 7.5 | A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no … | Sep 18, 2026 |
| CVE-2026-28199 | LOW | 3.3 | An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially … | Sep 18, 2026 |
| CVE-2026-28198 | HIGH | 8.8 | An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command … | Sep 18, 2026 |
| CVE-2026-28197 | HIGH | 8.8 | An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing … | Sep 18, 2026 |
| CVE-2026-21806 | LOW | 3.1 | HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative account, which … | Sep 18, 2026 |
| CVE-2026-93578 | MEDIUM | 5.9 | A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP … | Sep 18, 2026 |
| CVE-2026-93575 | HIGH | 7.5 | A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. The decoder … | Sep 18, 2026 |
| CVE-2026-93572 | HIGH | 7.5 | A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially crafted nested Redis (RESP) array headers. This … | Sep 18, 2026 |
| CVE-2026-93563 | HIGH | 7.5 | A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP server, could exploit this by sending … | Sep 18, 2026 |
| CVE-2026-93561 | MEDIUM | 6.5 | A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified … | Sep 18, 2026 |
| CVE-2026-81627 | MEDIUM | 6.7 | A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM … | Sep 18, 2026 |
| CVE-2026-92976 | UNKNOWN | — | A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite. An authenticated user could inject malicious HTML or JavaScript … | Sep 18, 2026 |
| CVE-2026-90884 | MEDIUM | 5.4 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all versions up to, and including, 10.8.1 … | Sep 18, 2026 |
| CVE-2026-87915 | HIGH | 7.2 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | Sep 18, 2026 |
| CVE-2026-87743 | HIGH | 7.5 | A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the security matcher and … | Sep 18, 2026 |
| CVE-2026-18405 | HIGH | 7.2 | The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | Sep 18, 2026 |
| CVE-2026-15797 | MEDIUM | 6.4 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | Sep 18, 2026 |
| CVE-2026-15579 | UNKNOWN | — | An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the username field length during Web login processing. This … | Sep 18, 2026 |
| CVE-2026-85410 | HIGH | 8.1 | The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to … | Sep 18, 2026 |
| CVE-2026-83561 | HIGH | 7.2 | The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Elementor Cookie Blocker Regex in all … | Sep 18, 2026 |