Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56672
Total
4490
Critical
16802
High
16633
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-81439 | LOW | 3.7 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, … | Sep 17, 2026 |
| CVE-2026-81438 | LOW | 3.7 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could … | Sep 17, 2026 |
| CVE-2026-66269 | HIGH | 7.3 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability. An unauthenticated attacker … | Sep 17, 2026 |
| CVE-2026-92894 | MEDIUM | 4.3 | A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target LookupValue record by ID without verifying it … | Sep 17, 2026 |
| CVE-2026-78428 | HIGH | 8.0 | For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login … | Sep 17, 2026 |
| CVE-2026-78427 | MEDIUM | 4.3 | The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the … | Sep 17, 2026 |
| CVE-2026-78426 | LOW | 3.7 | The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but … | Sep 17, 2026 |
| CVE-2026-78425 | UNKNOWN | — | Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they … | Sep 17, 2026 |
| CVE-2026-50610 | UNKNOWN | — | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense due to insufficient access controls in a privileged service. … | Sep 17, 2026 |
| CVE-2026-50609 | UNKNOWN | — | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. Insufficient access controls within a privileged Named Pipe service … | Sep 17, 2026 |
| CVE-2026-50608 | UNKNOWN | — | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication … | Sep 17, 2026 |
| CVE-2026-15688 | UNKNOWN | — | Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an … | Sep 17, 2026 |
| CVE-2026-87831 | MEDIUM | 4.3 | The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing … | Sep 17, 2026 |
| CVE-2026-87829 | MEDIUM | 4.3 | The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing … | Sep 17, 2026 |
| CVE-2026-86320 | HIGH | 7.8 | A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a … | Sep 17, 2026 |
| CVE-2026-50607 | UNKNOWN | — | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. A WebSocket service was configured to listen on all … | Sep 17, 2026 |
| CVE-2026-50606 | UNKNOWN | — | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a … | Sep 17, 2026 |
| CVE-2026-50605 | UNKNOWN | — | A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insufficient access controls within a privileged service may allow … | Sep 17, 2026 |
| CVE-2026-91017 | LOW | 3.7 | The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is … | Sep 17, 2026 |
| CVE-2026-90982 | MEDIUM | 5.3 | @fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4, on a case-insensitive filesystem such as Windows … | Sep 17, 2026 |
| CVE-2026-87963 | HIGH | 8.6 | The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and … | Sep 17, 2026 |
| CVE-2026-86801 | HIGH | 8.8 | The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and therefore applies no … | Sep 17, 2026 |
| CVE-2026-44940 | MEDIUM | 5.7 | The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access … | Sep 17, 2026 |
| CVE-2026-91019 | MEDIUM | 4.9 | The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level … | Sep 17, 2026 |
| CVE-2026-91016 | MEDIUM | 5.3 | The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated … | Sep 17, 2026 |