Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56672
Total
4490
Critical
16802
High
16633
Medium
CVE ID Severity Score Description Published
CVE-2026-20072 MEDIUM 4.9 A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are … Sep 16, 2026
CVE-2026-20071 LOW 3.8 A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco ISE could allow an unauthenticated, adjacent attacker to hijack the onboarding session of another user … Sep 16, 2026
CVE-2025-56566 UNKNOWN — MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage. An attacker with physical access to the device can extract … Sep 16, 2026
CVE-2025-56565 UNKNOWN — DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in cleartext within non-volatile memory. The exposed material includes SSH … Sep 16, 2026
CVE-2025-56563 UNKNOWN — A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts an attacker-controlled address URL parameter and passes it to … Sep 16, 2026
CVE-2026-92808 UNKNOWN — A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue … Sep 16, 2026
CVE-2026-92526 MEDIUM 6.3 A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/leave/index.php. Executing a manipulation of the … Sep 16, 2026
CVE-2026-92475 MEDIUM 5.3 A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utils/downloader.c. This manipulation of the argument Content-Range causes out-of-bounds … Sep 16, 2026
CVE-2026-92474 LOW 3.3 A security flaw has been discovered in GPAC 26.08-DEV. This affects the function gf_inline_get_proto_lib of the file src/compositor/mpeg4_inline.c of the component Proto Link Handler. The … Sep 16, 2026
CVE-2026-89084 UNKNOWN — HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under … Sep 16, 2026
CVE-2026-89083 UNKNOWN — HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under … Sep 16, 2026
CVE-2026-89082 UNKNOWN — HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under … Sep 16, 2026
CVE-2026-88592 UNKNOWN — kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file proxy endpoint /getCorsFile is protected by TrustHostFilter against the trust.host whitelist. However, … Sep 16, 2026
CVE-2026-87976 UNKNOWN — Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR … Sep 16, 2026
CVE-2026-87116 MEDIUM 6.5 Tanium addressed a server-side request forgery vulnerability in Threat Response. Sep 16, 2026
CVE-2026-87113 MEDIUM 6.3 Tanium addressed an improper access controls vulnerability in Threat Response. Sep 16, 2026
CVE-2026-87105 HIGH 8.8 Tanium addressed a SQL injection vulnerability in Threat Response. Sep 16, 2026
CVE-2026-87076 MEDIUM 6.5 Tanium addressed an information disclosure vulnerability in Discover. Sep 16, 2026
CVE-2026-87026 LOW 3.8 Tanium addressed an improper access controls vulnerability in Threat Response. Sep 16, 2026
CVE-2026-87024 HIGH 7.2 Tanium addressed a SQL injection vulnerability in Asset. Sep 16, 2026
CVE-2026-86865 HIGH 7.2 Tanium addressed a SQL injection vulnerability in Asset. Sep 16, 2026
CVE-2026-86831 HIGH 8.7 Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authenticated remote user to bypass NetworkPolicy … Sep 16, 2026
CVE-2026-86089 UNKNOWN — Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and … Sep 16, 2026
CVE-2026-82561 UNKNOWN — Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process … Sep 16, 2026
CVE-2026-81870 UNKNOWN — OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively … Sep 16, 2026