Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56576
Total
4483
Critical
16766
High
16609
Medium
CVE ID Severity Score Description Published
CVE-2026-82759 UNKNOWN — Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audit store to recover the client IP addresses … Sep 17, 2026
CVE-2026-82723 UNKNOWN — Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers of the audit store. The audit_log … Sep 17, 2026
CVE-2026-82685 UNKNOWN — Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and confirm another user's email address, and so take over … Sep 17, 2026
CVE-2026-81829 MEDIUM 5.3 A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When … Sep 17, 2026
CVE-2026-81637 UNKNOWN — Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim … Sep 17, 2026
CVE-2026-81632 UNKNOWN — Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to … Sep 17, 2026
CVE-2026-81453 MEDIUM 6.5 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged … Sep 17, 2026
CVE-2026-81443 MEDIUM 6.4 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit … Sep 17, 2026
CVE-2026-81442 HIGH 8.1 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this … Sep 17, 2026
CVE-2026-80355 MEDIUM 5.4 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this … Sep 17, 2026
CVE-2026-80218 UNKNOWN — Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of … Sep 17, 2026
CVE-2026-78528 MEDIUM 5.3 Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions. Sep 17, 2026
CVE-2026-78295 HIGH 8.8 Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions. Sep 17, 2026
CVE-2026-78294 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions. Sep 17, 2026
CVE-2026-78223 UNKNOWN — Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows … Sep 17, 2026
CVE-2026-74017 MEDIUM 5.3 Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions. Sep 17, 2026
CVE-2026-74005 MEDIUM 5.4 Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions. Sep 17, 2026
CVE-2026-74002 MEDIUM 5.3 Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions. Sep 17, 2026
CVE-2026-74000 MEDIUM 5.3 Contributor Broken Access Control in Simple Membership <= 4.8.2 versions. Sep 17, 2026
CVE-2026-73999 MEDIUM 5.4 Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions. Sep 17, 2026
CVE-2026-71568 MEDIUM 5.3 In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, … Sep 17, 2026
CVE-2026-66676 MEDIUM 5.3 Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions. Sep 17, 2026
CVE-2026-66631 HIGH 7.6 Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions. Sep 17, 2026
CVE-2026-66630 HIGH 7.6 Administrator SQL Injection in PublishPress Series <= 3.1.3 versions. Sep 17, 2026
CVE-2026-66628 HIGH 7.6 Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions. Sep 17, 2026