Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56820
Total
4503
Critical
16867
High
16681
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-63325 | HIGH | 7.8 | Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/respect-core and @redocly/cli, the respect command dynamically evaluates $faker runtime … | Sep 16, 2026 |
| CVE-2026-63225 | MEDIUM | 4.4 | Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the split command constructs output paths under --outDir from untrusted OpenAPI … | Sep 16, 2026 |
| CVE-2026-63126 | HIGH | 7.5 | Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire protobuf readers do not consistently validate attacker-controlled … | Sep 16, 2026 |
| CVE-2026-59823 | UNKNOWN | — | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated LiteLLM Proxy caller with … | Sep 16, 2026 |
| CVE-2026-46352 | HIGH | 7.5 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, Suricata's … | Sep 16, 2026 |
| CVE-2026-38999 | UNKNOWN | — | A Null Pointer Dereference in the mk_sched_event_close function (mk_server/mk_scheduler.c) of Monkey through commit 4fb0c16 allows attackers to cause a Denial of Service (DoS) via sending … | Sep 16, 2026 |
| CVE-2026-92720 | CRITICAL | 9.1 | Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthenticated attackers to read webhook secrets and service URLs. Attackers can … | Sep 16, 2026 |
| CVE-2026-92719 | HIGH | 7.5 | Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing attackers to make the node issue … | Sep 16, 2026 |
| CVE-2026-92718 | HIGH | 7.3 | Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious … | Sep 16, 2026 |
| CVE-2026-92717 | CRITICAL | 9.1 | Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token. Attackers … | Sep 16, 2026 |
| CVE-2026-92716 | CRITICAL | 9.6 | Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint that allows administrators to reset and read API keys of non-administrator users … | Sep 16, 2026 |
| CVE-2026-92605 | MEDIUM | 6.5 | IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers with access to … | Sep 16, 2026 |
| CVE-2026-92604 | HIGH | 8.1 | Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows default User role users to write attacker-controlled JSON … | Sep 16, 2026 |
| CVE-2026-92416 | MEDIUM | 4.3 | A vulnerability has been found in Open5GS up to 2.8.0. Affected by this issue is the function smf_n4_handle_session_report_request of the file src/smf/n4-handler.c of the component … | Sep 16, 2026 |
| CVE-2026-92413 | MEDIUM | 4.3 | A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the file pdf-stream.c of the … | Sep 16, 2026 |
| CVE-2026-92406 | HIGH | 7.3 | A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown function of the file /admins/assessments/databank/btn_functions.php?action=add. Performing a manipulation … | Sep 16, 2026 |
| CVE-2026-88593 | UNKNOWN | — | kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes the user-controlled page and kkagent request parameters to FreeMarker templates without … | Sep 16, 2026 |
| CVE-2026-85387 | UNKNOWN | — | Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the state of the account the token … | Sep 16, 2026 |
| CVE-2026-84397 | MEDIUM | 5.4 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into … | Sep 16, 2026 |
| CVE-2026-69147 | MEDIUM | 6.5 | vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to … | Sep 16, 2026 |
| CVE-2026-51990 | UNKNOWN | — | An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component | Sep 16, 2026 |
| CVE-2026-47094 | HIGH | 8.8 | SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vulnerability that allows authenticated attackers to access and modify arbitrary employee records due to missing … | Sep 16, 2026 |
| CVE-2026-18120 | UNKNOWN | — | Concrete CMS before 9.5.3 exposed a legacy Express entry search endpoint that returned entry result JSON without invoking the canViewExpressEntries() permission check applied by the … | Sep 16, 2026 |
| CVE-2026-92603 | MEDIUM | 6.5 | ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages and … | Sep 16, 2026 |
| CVE-2026-92602 | HIGH | 7.1 | TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController. Authenticated attackers can attach webhooks to other … | Sep 16, 2026 |