Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56334
Total
4455
Critical
16700
High
16518
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-93312 | MEDIUM | 4.3 | A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It … | Sep 18, 2026 |
| CVE-2026-93311 | MEDIUM | 4.3 | A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The manipulation of … | Sep 18, 2026 |
| CVE-2026-93310 | MEDIUM | 5.3 | A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. The manipulation leads to allocation of … | Sep 18, 2026 |
| CVE-2026-79954 | UNKNOWN | — | NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely … | Sep 18, 2026 |
| CVE-2026-93454 | MEDIUM | 5.4 | Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term … | Sep 18, 2026 |
| CVE-2026-93453 | HIGH | 8.3 | SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers … | Sep 18, 2026 |
| CVE-2026-93452 | HIGH | 7.5 | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data … | Sep 18, 2026 |
| CVE-2026-93451 | MEDIUM | 6.5 | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass … | Sep 18, 2026 |
| CVE-2026-93450 | HIGH | 7.5 | go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated … | Sep 18, 2026 |
| CVE-2026-93309 | MEDIUM | 4.3 | A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of the component VES Collector. Executing a manipulation … | Sep 18, 2026 |
| CVE-2026-93308 | MEDIUM | 4.3 | A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the component VES Collector. Performing a manipulation … | Sep 18, 2026 |
| CVE-2026-85887 | HIGH | 7.7 | Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network. | Sep 18, 2026 |
| CVE-2026-85878 | CRITICAL | 9.9 | Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network. | Sep 18, 2026 |
| CVE-2026-83946 | HIGH | 8.2 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network. | Sep 18, 2026 |
| CVE-2026-69843 | CRITICAL | 10.0 | Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network. | Sep 18, 2026 |
| CVE-2026-62874 | CRITICAL | 10.0 | Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network. | Sep 18, 2026 |
| CVE-2026-2585 | MEDIUM | 6.4 | The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ parameter in all versions up to, and including, … | Sep 18, 2026 |
| CVE-2026-18441 | MEDIUM | 4.3 | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions … | Sep 18, 2026 |
| CVE-2026-93436 | HIGH | 7.5 | vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit requests with max_tokens=0 … | Sep 17, 2026 |
| CVE-2026-93435 | HIGH | 7.5 | redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through … | Sep 17, 2026 |
| CVE-2026-87886 | HIGH | 7.8 | Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis … | Sep 17, 2026 |
| CVE-2026-87701 | CRITICAL | 9.6 | Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over … | Sep 17, 2026 |
| CVE-2026-85917 | HIGH | 7.5 | Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | Sep 17, 2026 |
| CVE-2026-85889 | CRITICAL | 10.0 | Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | Sep 17, 2026 |
| CVE-2026-85885 | CRITICAL | 9.9 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network. | Sep 17, 2026 |