Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56576
Total
4483
Critical
16766
High
16609
Medium
CVE ID Severity Score Description Published
CVE-2026-54575 UNKNOWN — mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used race-prone path handling across libmport/fetch.c, libmport/clean.c, libmport/util.c, libmport/bundle_read_install_pkg.c, libmport/delete_primative.c, … Sep 17, 2026
CVE-2026-28326 HIGH 8.8 SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key. Sep 17, 2026
CVE-2026-93015 MEDIUM 6.3 BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream endpoint discovery. A bonded peer can send an … Sep 17, 2026
CVE-2026-93014 HIGH 7.1 RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing authenticated users to unlink allow-listed files via path … Sep 17, 2026
CVE-2026-93013 MEDIUM 4.3 RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary files by supplying absolute … Sep 17, 2026
CVE-2026-92881 MEDIUM 4.3 A security vulnerability has been detected in vgmstream. The affected element is the function init_vgmstream_awb_memory of the file src/meta/awb.c of the component AWB parser. Such … Sep 17, 2026
CVE-2026-91039 UNKNOWN — Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identity-provider connection of a dynamic_oidc strategy to be signed in as … Sep 17, 2026
CVE-2026-89036 HIGH 8.8 Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticated users with functions.write or sites.write permissions to execute arbitrary commands by injecting TAB characters … Sep 17, 2026
CVE-2026-86864 HIGH 8.8 pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without … Sep 17, 2026
CVE-2026-86863 CRITICAL 9.8 pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through … Sep 17, 2026
CVE-2026-86862 MEDIUM 6.5 pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql. libpq … Sep 17, 2026
CVE-2026-86861 MEDIUM 5.9 pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the … Sep 17, 2026
CVE-2026-86040 HIGH 7.5 libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floodsub accepts unauthenticated RPC frames on /floodsub/1.0.0 through PeerStreams.attachInboundStream in packages/floodsub/src/peer-streams.ts without … Sep 17, 2026
CVE-2026-86039 HIGH 8.2 libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in packages/peer-store/src/index.ts uses consumePeerRecord to verify a RecordEnvelope signature but … Sep 17, 2026
CVE-2026-86038 HIGH 7.5 libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses the default StrictSign policy in packages/gossipsub/src/utils/buildRawMessage.ts, where validateToRawMessage verifies … Sep 17, 2026
CVE-2026-86000 MEDIUM 5.3 Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src/soupsieve/css_parser.py defines IDENTIFIER … Sep 17, 2026
CVE-2026-85999 MEDIUM 5.3 Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsieve/css_parser.py trims the raw selector … Sep 17, 2026
CVE-2026-85721 HIGH 7.5 The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response … Sep 17, 2026
CVE-2026-85719 HIGH 7.5 The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.1.0 until 2.16.1 and 3.0.12, requests using … Sep 17, 2026
CVE-2026-85718 MEDIUM 5.9 The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, a client with maxConnections … Sep 17, 2026
CVE-2026-85717 MEDIUM 6.8 The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.14.5 to 2.16.0 and from 3.0.9 to … Sep 17, 2026
CVE-2026-85715 HIGH 7.5 ExifReader is a JavaScript Exif information parser. Prior to 4.41.1, ExifReader parses attacker-controlled HEIC or AVIF ISO-BMFF files in getItems() within src/image-header-iso-bmff-iloc.js and trusts iloc … Sep 17, 2026
CVE-2026-81868 MEDIUM 6.5 Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() … Sep 17, 2026
CVE-2026-81516 HIGH 7.5 Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. From 4.0.0 until 4.3.0, ConsulDiscoveryClient constructs ConsulServiceInstance … Sep 17, 2026
CVE-2026-81515 HIGH 7.5 Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. From 4.0.0 until 4.3.0, EurekaDiscoveryClient deserializes the … Sep 17, 2026