Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56672
Total
4490
Critical
16802
High
16633
Medium
CVE ID Severity Score Description Published
CVE-2026-92764 MEDIUM 4.3 OpenCVE before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships. Attackers with organization-scoped tokens … Sep 16, 2026
CVE-2026-92763 HIGH 8.1 Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with only the import action can … Sep 16, 2026
CVE-2026-92762 HIGH 8.8 Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks. Attackers with startup.read permission can craft … Sep 16, 2026
CVE-2026-92761 HIGH 8.8 WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform privileged actions. Attackers with read-only grants can power off virtual … Sep 16, 2026
CVE-2026-92760 MEDIUM 6.5 Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics. Attackers with … Sep 16, 2026
CVE-2026-92759 MEDIUM 6.5 SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses. View-only product … Sep 16, 2026
CVE-2026-92754 MEDIUM 4.3 PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out. Authenticated attackers with … Sep 16, 2026
CVE-2026-92753 HIGH 7.1 PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event … Sep 16, 2026
CVE-2026-92752 HIGH 8.3 metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissions. Attackers can enumerate sequential document identifiers to read, replace, … Sep 16, 2026
CVE-2026-92751 HIGH 8.1 CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators. Attackers can craft … Sep 16, 2026
CVE-2026-92750 MEDIUM 6.5 Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticated users to retrieve provider configurations from spaces they do not … Sep 16, 2026
CVE-2026-92749 HIGH 8.1 SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline. Unauthenticated remote attackers who … Sep 16, 2026
CVE-2026-92748 HIGH 8.8 BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on … Sep 16, 2026
CVE-2026-92527 MEDIUM 6.3 A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbacks_controller.rb of the component Shopify OAuth. The … Sep 16, 2026
CVE-2026-81872 UNKNOWN — OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the go.opentelemetry.io/otel/sdk/log BatchingProcessor can enter a tight CPU loop when attacker-driven log emission fills … Sep 16, 2026
CVE-2026-81871 UNKNOWN — OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate environment variables through loadEnvTLS … Sep 16, 2026
CVE-2026-81869 UNKNOWN — OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attribute truncation path can fail to enforce AttributeValueLengthLimit for string and … Sep 16, 2026
CVE-2026-76460 CRITICAL 10.0 A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to … Sep 16, 2026
CVE-2026-76451 MEDIUM 4.9 A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL … Sep 16, 2026
CVE-2026-76450 MEDIUM 4.9 A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL … Sep 16, 2026
CVE-2026-76449 MEDIUM 4.9 A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL … Sep 16, 2026
CVE-2026-76448 MEDIUM 4.9 A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL … Sep 16, 2026
CVE-2026-76447 MEDIUM 5.3 A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to cause an … Sep 16, 2026
CVE-2026-76446 MEDIUM 4.9 A vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read specific files on the underlying operating system … Sep 16, 2026
CVE-2026-76444 MEDIUM 5.3 A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an … Sep 16, 2026