Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56672
Total
4490
Critical
16802
High
16633
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-92764 | MEDIUM | 4.3 | OpenCVE before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships. Attackers with organization-scoped tokens … | Sep 16, 2026 |
| CVE-2026-92763 | HIGH | 8.1 | Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with only the import action can … | Sep 16, 2026 |
| CVE-2026-92762 | HIGH | 8.8 | Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks. Attackers with startup.read permission can craft … | Sep 16, 2026 |
| CVE-2026-92761 | HIGH | 8.8 | WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform privileged actions. Attackers with read-only grants can power off virtual … | Sep 16, 2026 |
| CVE-2026-92760 | MEDIUM | 6.5 | Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics. Attackers with … | Sep 16, 2026 |
| CVE-2026-92759 | MEDIUM | 6.5 | SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses. View-only product … | Sep 16, 2026 |
| CVE-2026-92754 | MEDIUM | 4.3 | PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out. Authenticated attackers with … | Sep 16, 2026 |
| CVE-2026-92753 | HIGH | 7.1 | PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event … | Sep 16, 2026 |
| CVE-2026-92752 | HIGH | 8.3 | metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissions. Attackers can enumerate sequential document identifiers to read, replace, … | Sep 16, 2026 |
| CVE-2026-92751 | HIGH | 8.1 | CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators. Attackers can craft … | Sep 16, 2026 |
| CVE-2026-92750 | MEDIUM | 6.5 | Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticated users to retrieve provider configurations from spaces they do not … | Sep 16, 2026 |
| CVE-2026-92749 | HIGH | 8.1 | SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline. Unauthenticated remote attackers who … | Sep 16, 2026 |
| CVE-2026-92748 | HIGH | 8.8 | BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on … | Sep 16, 2026 |
| CVE-2026-92527 | MEDIUM | 6.3 | A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbacks_controller.rb of the component Shopify OAuth. The … | Sep 16, 2026 |
| CVE-2026-81872 | UNKNOWN | — | OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the go.opentelemetry.io/otel/sdk/log BatchingProcessor can enter a tight CPU loop when attacker-driven log emission fills … | Sep 16, 2026 |
| CVE-2026-81871 | UNKNOWN | — | OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate environment variables through loadEnvTLS … | Sep 16, 2026 |
| CVE-2026-81869 | UNKNOWN | — | OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation path can fail to enforce AttributeValueLengthLimit for string and … | Sep 16, 2026 |
| CVE-2026-76460 | CRITICAL | 10.0 | A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to … | Sep 16, 2026 |
| CVE-2026-76451 | MEDIUM | 4.9 | A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL … | Sep 16, 2026 |
| CVE-2026-76450 | MEDIUM | 4.9 | A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL … | Sep 16, 2026 |
| CVE-2026-76449 | MEDIUM | 4.9 | A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL … | Sep 16, 2026 |
| CVE-2026-76448 | MEDIUM | 4.9 | A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL … | Sep 16, 2026 |
| CVE-2026-76447 | MEDIUM | 5.3 | A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to cause an … | Sep 16, 2026 |
| CVE-2026-76446 | MEDIUM | 4.9 | A vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read specific files on the underlying operating system … | Sep 16, 2026 |
| CVE-2026-76444 | MEDIUM | 5.3 | A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an … | Sep 16, 2026 |