Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56672
Total
4490
Critical
16802
High
16633
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-91106 | UNKNOWN | — | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege … | Sep 16, 2026 |
| CVE-2026-91105 | UNKNOWN | — | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege … | Sep 16, 2026 |
| CVE-2026-91104 | UNKNOWN | — | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege … | Sep 16, 2026 |
| CVE-2026-91103 | UNKNOWN | — | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege … | Sep 16, 2026 |
| CVE-2026-91102 | UNKNOWN | — | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege … | Sep 16, 2026 |
| CVE-2026-91101 | UNKNOWN | — | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege … | Sep 16, 2026 |
| CVE-2026-91100 | UNKNOWN | — | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege … | Sep 16, 2026 |
| CVE-2026-91099 | UNKNOWN | — | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege … | Sep 16, 2026 |
| CVE-2026-91098 | UNKNOWN | — | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege … | Sep 16, 2026 |
| CVE-2026-91097 | UNKNOWN | — | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege … | Sep 16, 2026 |
| CVE-2026-86071 | LOW | 3.7 | Junrar is an open source Java RAR archive library. Prior to version 7.6.1, LocalFolderExtractor in src/main/java/com/github/junrar/LocalFolderExtractor.java can create directories outside the intended extraction root when … | Sep 16, 2026 |
| CVE-2026-86043 | HIGH | 7.5 | Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWithBody filter can authorize an oversized request after Skipper … | Sep 16, 2026 |
| CVE-2026-86003 | HIGH | 7.5 | CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC listeners in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call dns.Msg.Unpack … | Sep 16, 2026 |
| CVE-2026-82399 | HIGH | 7.5 | CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC request paths in plugin/pkg/doh/doh.go, core/dnsserver/server_quic.go, and core/dnsserver/server_grpc.go call … | Sep 16, 2026 |
| CVE-2026-81876 | HIGH | 7.5 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can enter … | Sep 16, 2026 |
| CVE-2026-81875 | HIGH | 7.5 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can consume … | Sep 16, 2026 |
| CVE-2026-81176 | MEDIUM | 5.3 | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. Prior to 5.9.2, devalue.parse does not reject … | Sep 16, 2026 |
| CVE-2026-79298 | HIGH | 8.4 | An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and fixed in v.11.3.0.34 allows a local attcker to execute arbitrary code via the … | Sep 16, 2026 |
| CVE-2026-77360 | UNKNOWN | — | oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.8, the @orpc/server CORS plugin in … | Sep 16, 2026 |
| CVE-2026-75516 | UNKNOWN | — | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.34.0, AMQConnection.start() applies Math.min(maxInboundMessageBodySize, frameMax) … | Sep 16, 2026 |
| CVE-2026-75025 | MEDIUM | 4.7 | Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict server-rendered content from accessing local or private network resources. … | Sep 16, 2026 |
| CVE-2026-73462 | MEDIUM | 6.5 | On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can … | Sep 16, 2026 |
| CVE-2026-73457 | MEDIUM | 5.3 | Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in … | Sep 16, 2026 |
| CVE-2026-73456 | CRITICAL | 10.0 | Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious … | Sep 16, 2026 |
| CVE-2026-73443 | MEDIUM | 4.7 | On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is … | Sep 16, 2026 |