Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56576
Total
4483
Critical
16766
High
16609
Medium
CVE ID Severity Score Description Published
CVE-2026-92903 HIGH 8.2 Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be interpolated into SQL strings that are executed as multi-statement … Sep 17, 2026
CVE-2026-92893 MEDIUM 4.3 A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an unscoped Host.where call that does not … Sep 17, 2026
CVE-2026-92611 UNKNOWN — In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead … Sep 17, 2026
CVE-2026-81474 HIGH 7.8 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A low privileged attacker with local access could potentially exploit this … Sep 17, 2026
CVE-2026-81439 LOW 3.7 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, … Sep 17, 2026
CVE-2026-81438 LOW 3.7 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could … Sep 17, 2026
CVE-2026-66269 HIGH 7.3 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability. An unauthenticated attacker … Sep 17, 2026
CVE-2026-92894 MEDIUM 4.3 A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target LookupValue record by ID without verifying it … Sep 17, 2026
CVE-2026-78428 HIGH 8.0 For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login … Sep 17, 2026
CVE-2026-78427 MEDIUM 4.3 The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the … Sep 17, 2026
CVE-2026-78426 LOW 3.7 The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but … Sep 17, 2026
CVE-2026-78425 UNKNOWN — Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they … Sep 17, 2026
CVE-2026-50610 UNKNOWN — A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense due to insufficient access controls in a privileged service. … Sep 17, 2026
CVE-2026-50609 UNKNOWN — A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. Insufficient access controls within a privileged Named Pipe service … Sep 17, 2026
CVE-2026-50608 UNKNOWN — A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication … Sep 17, 2026
CVE-2026-15688 UNKNOWN — Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an … Sep 17, 2026
CVE-2026-87831 MEDIUM 4.3 The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing … Sep 17, 2026
CVE-2026-87829 MEDIUM 4.3 The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing … Sep 17, 2026
CVE-2026-86320 HIGH 7.8 A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a … Sep 17, 2026
CVE-2026-50607 UNKNOWN — A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. A WebSocket service was configured to listen on all … Sep 17, 2026
CVE-2026-50606 UNKNOWN — A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a … Sep 17, 2026
CVE-2026-50605 UNKNOWN — A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insufficient access controls within a privileged service may allow … Sep 17, 2026
CVE-2026-91017 LOW 3.7 The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is … Sep 17, 2026
CVE-2026-90982 MEDIUM 5.3 @fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4, on a case-insensitive filesystem such as Windows … Sep 17, 2026
CVE-2026-87963 HIGH 8.6 The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and … Sep 17, 2026