Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56672
Total
4490
Critical
16802
High
16633
Medium
CVE ID Severity Score Description Published
CVE-2026-76439 MEDIUM 5.3 A vulnerability in the endpoint posture status reporting functionality of the guest portal web application of Cisco ISE could allow an unauthenticated, remote attacker to … Sep 16, 2026
CVE-2026-76438 MEDIUM 6.5 A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations … Sep 16, 2026
CVE-2026-76434 MEDIUM 4.9 A vulnerability in the certificate import functionality of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to … Sep 16, 2026
CVE-2026-76433 MEDIUM 5.3 A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to access protected files on … Sep 16, 2026
CVE-2026-76432 MEDIUM 4.9 A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with administrative-level privileges to write arbitrary … Sep 16, 2026
CVE-2026-76431 MEDIUM 4.9 A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to … Sep 16, 2026
CVE-2026-76428 MEDIUM 4.9 A vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the … Sep 16, 2026
CVE-2026-76427 MEDIUM 4.9 A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files that are stored on … Sep 16, 2026
CVE-2026-76426 MEDIUM 4.9 A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the … Sep 16, 2026
CVE-2026-76425 HIGH 7.6 A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability … Sep 16, 2026
CVE-2026-76424 HIGH 7.2 A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device. … Sep 16, 2026
CVE-2026-76413 HIGH 8.2 A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to … Sep 16, 2026
CVE-2026-76412 HIGH 8.5 A vulnerability in the remote diagnostics debugger of Cisco Secure FMC Software could allow an authenticated, remote attacker to enable the remote diagnostics debugger service. … Sep 16, 2026
CVE-2026-76409 HIGH 8.8 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. … Sep 16, 2026
CVE-2026-75513 CRITICAL 9.1 Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marten LINQ and tenant-management paths interpolate runtime, … Sep 16, 2026
CVE-2026-63506 HIGH 8.8 Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the … Sep 16, 2026
CVE-2026-62997 UNKNOWN — Kedro-Datasets provides data connectors for Kedro. From version 5.0.0 until 9.5.0, kedro_datasets_experimental.pytorch.PyTorchDataset in kedro-datasets loads .pt model files with torch.load without enforcing weights_only=True, and user-supplied … Sep 16, 2026
CVE-2026-20360 HIGH 8.8 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. … Sep 16, 2026
CVE-2026-20352 HIGH 8.6 A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) … Sep 16, 2026
CVE-2026-20350 MEDIUM 4.7 A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to inject arbitrary operating system commands. This … Sep 16, 2026
CVE-2026-20344 HIGH 8.8 A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to perform a SQL injection attack against … Sep 16, 2026
CVE-2026-20343 HIGH 7.5 A vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to download sensitive files and use unbounded disk … Sep 16, 2026
CVE-2026-20342 HIGH 7.7 A vulnerability in a specific file download API of Cisco Secure FMC Software could allow an authenticated, remote attacker to download arbitrary files from an … Sep 16, 2026
CVE-2026-20340 HIGH 8.8 A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands at the root privilege level. This vulnerability is due … Sep 16, 2026
CVE-2026-20336 HIGH 8.8 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software … Sep 16, 2026