Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56576
Total
4483
Critical
16766
High
16609
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-92918 | HIGH | 8.8 | admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the … | Sep 17, 2026 |
| CVE-2026-92904 | MEDIUM | 4.3 | A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller's view_job_invocations … | Sep 17, 2026 |
| CVE-2026-81481 | HIGH | 7.5 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker … | Sep 17, 2026 |
| CVE-2026-53681 | UNKNOWN | — | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. | Sep 17, 2026 |
| CVE-2026-92925 | HIGH | 7.1 | A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying … | Sep 17, 2026 |
| CVE-2026-92917 | HIGH | 7.5 | Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and serialize filters (print_r, vardump, json_encode, … | Sep 17, 2026 |
| CVE-2026-92916 | HIGH | 7.5 | Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.debugger.enabled: true, which is not the … | Sep 17, 2026 |
| CVE-2026-92915 | HIGH | 7.3 | WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVerifyEmail.php. The script disables the login requirement ($global['ignoreUserMustBeLoggedIn'] = … | Sep 17, 2026 |
| CVE-2026-92914 | HIGH | 8.1 | AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares challenge responses using loose equality against an uninitialized session variable. … | Sep 17, 2026 |
| CVE-2026-92913 | HIGH | 7.4 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generator when creating account activation / login pairing codes. getRandomCode() in objects/functions.php derives the code … | Sep 17, 2026 |
| CVE-2026-92912 | MEDIUM | 6.5 | AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in LiveTransmition, reducing key entropy to approximately one million possibilities per creation second. … | Sep 17, 2026 |
| CVE-2026-92860 | CRITICAL | 9.1 | A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fmt.Sprintf of the file /api/security/quick-setup of … | Sep 17, 2026 |
| CVE-2026-90823 | CRITICAL | 9.8 | FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass. An unauthenticated remote attacker with access … | Sep 17, 2026 |
| CVE-2026-90822 | CRITICAL | 9.8 | FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability in the xtremed daemon. An unauthenticated remote … | Sep 17, 2026 |
| CVE-2026-81480 | HIGH | 7.2 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this … | Sep 17, 2026 |
| CVE-2026-81479 | MEDIUM | 5.8 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability. A low privileged attacker with local access could potentially exploit this … | Sep 17, 2026 |
| CVE-2026-81478 | HIGH | 8.1 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit … | Sep 17, 2026 |
| CVE-2026-81477 | HIGH | 7.2 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this … | Sep 17, 2026 |
| CVE-2026-81476 | HIGH | 8.1 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An … | Sep 17, 2026 |
| CVE-2026-81475 | HIGH | 8.1 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit … | Sep 17, 2026 |
| CVE-2026-81441 | MEDIUM | 4.0 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with local access could potentially exploit … | Sep 17, 2026 |
| CVE-2026-81440 | HIGH | 7.3 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this … | Sep 17, 2026 |
| CVE-2026-78296 | MEDIUM | 5.3 | Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. This issue affects FluentAuth: from n/a through 2.1.2. | Sep 17, 2026 |
| CVE-2026-53679 | UNKNOWN | — | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. | Sep 17, 2026 |
| CVE-2026-11874 | UNKNOWN | — | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. | Sep 17, 2026 |