Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56576
Total
4483
Critical
16766
High
16609
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-76834 | HIGH | 8.1 | b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative … | Sep 17, 2026 |
| CVE-2026-76781 | MEDIUM | 5.5 | A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during … | Sep 17, 2026 |
| CVE-2026-75588 | LOW | 2.6 | Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected server, which … | Sep 17, 2026 |
| CVE-2026-75523 | MEDIUM | 5.9 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint … | Sep 17, 2026 |
| CVE-2026-69197 | UNKNOWN | — | Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.0.2, the Content Delivery API applies member and Public Access checks to the directly requested … | Sep 17, 2026 |
| CVE-2026-61700 | LOW | 3.7 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, ClientMessage.readPacket processes a … | Sep 17, 2026 |
| CVE-2026-56795 | HIGH | 8.2 | Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit … | Sep 17, 2026 |
| CVE-2026-12284 | LOW | 3.7 | Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or … | Sep 17, 2026 |
| CVE-2026-92987 | HIGH | 7.5 | roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML parsing without limits on attribute count. Attackers can craft XML documents with tens of … | Sep 17, 2026 |
| CVE-2026-92986 | HIGH | 8.8 | SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. Attackers can set malicious titles through the rename … | Sep 17, 2026 |
| CVE-2026-92985 | HIGH | 8.8 | SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock tree. Attackers can craft malicious .sy … | Sep 17, 2026 |
| CVE-2026-92984 | HIGH | 8.1 | HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated attackers to fixate victim sessions. Attackers … | Sep 17, 2026 |
| CVE-2026-92983 | HIGH | 7.5 | InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user-facing session IDs instead of internal scheduler … | Sep 17, 2026 |
| CVE-2026-92880 | MEDIUM | 6.3 | A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the component EA SCHl parser. … | Sep 17, 2026 |
| CVE-2026-88952 | UNKNOWN | — | Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another user by linking an OAuth2 identity to an account that … | Sep 17, 2026 |
| CVE-2026-87742 | HIGH | 7.5 | A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by streaming messages over a single … | Sep 17, 2026 |
| CVE-2026-85078 | MEDIUM | 6.5 | Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does not fully consume the trailer-part after the terminating zero … | Sep 17, 2026 |
| CVE-2026-85077 | HIGH | 8.2 | Sanic is an opensource python web server/framework. Prior to version 24.12.1, and in version 25.12.0, the HTTP/1.1 response pipeline in sanic/response/types.py serializes response header names … | Sep 17, 2026 |
| CVE-2026-81447 | MEDIUM | 6.8 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this … | Sep 17, 2026 |
| CVE-2026-81446 | HIGH | 7.4 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this … | Sep 17, 2026 |
| CVE-2026-81445 | HIGH | 7.2 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this … | Sep 17, 2026 |
| CVE-2026-80356 | HIGH | 7.3 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with local … | Sep 17, 2026 |
| CVE-2026-79752 | UNKNOWN | — | CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled … | Sep 17, 2026 |
| CVE-2026-77614 | HIGH | 8.8 | Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to versions 19.7 and 20.2, the default security … | Sep 17, 2026 |
| CVE-2026-71538 | UNKNOWN | — | @cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. Prior to version 6.0.0, the Windows fallback path in src/npmRunner.ts, used when npm_execpath does not … | Sep 17, 2026 |