Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56820
Total
4503
Critical
16867
High
16681
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-92601 | MEDIUM | 6.5 | Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission defaults to false and is not overridden by any action methods. Authenticated … | Sep 16, 2026 |
| CVE-2026-92600 | MEDIUM | 6.5 | Guns through 8.3.5 contains an information disclosure vulnerability in SysUserController where /sysUser/detail and /sysUser/page endpoints omit requiredPermission configuration, causing the permission interceptor to skip RBAC … | Sep 16, 2026 |
| CVE-2026-92405 | HIGH | 7.3 | A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element is an unknown function of the file /index.php. Such … | Sep 16, 2026 |
| CVE-2026-92402 | MEDIUM | 6.3 | A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affects the function index of the file UserController.java of the component … | Sep 16, 2026 |
| CVE-2026-92401 | HIGH | 7.3 | A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects the function top.upstudy.crm.utils.LoginUserUtil.releaseUserIdFromCookie. The manipulation leads to improper authentication. The attack can … | Sep 16, 2026 |
| CVE-2026-92399 | HIGH | 7.3 | A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utils/rmt_ws.c of the component WebSocket Handler. Executing a manipulation of … | Sep 16, 2026 |
| CVE-2026-92398 | CRITICAL | 9.1 | A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admin of the component user_list_note Module. … | Sep 16, 2026 |
| CVE-2026-87031 | UNKNOWN | — | n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of concrete/src/Api/Controller/Users.php) did not perform a permission check … | Sep 16, 2026 |
| CVE-2026-87028 | UNKNOWN | — | Concrete CMS 9 through 9.5.3 did not confirm that a board InstanceItem submitted to the custom-slot preview endpoint belonged to the board instance the requesting … | Sep 16, 2026 |
| CVE-2026-86359 | HIGH | 8.5 | Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, … | Sep 16, 2026 |
| CVE-2026-86358 | MEDIUM | 6.5 | Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this … | Sep 16, 2026 |
| CVE-2026-85756 | HIGH | 7.5 | SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into the command used to run scp on … | Sep 16, 2026 |
| CVE-2026-85732 | MEDIUM | 4.7 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link … | Sep 16, 2026 |
| CVE-2026-85731 | HIGH | 8.8 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store … | Sep 16, 2026 |
| CVE-2026-85386 | UNKNOWN | — | Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload question. Plain XML uploads were validated by … | Sep 16, 2026 |
| CVE-2026-85385 | UNKNOWN | — | Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output encoding on the Dashboard user management … | Sep 16, 2026 |
| CVE-2026-84993 | MEDIUM | 6.5 | MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to 6.6.16 and 7.1.7, the shared … | Sep 16, 2026 |
| CVE-2026-76420 | CRITICAL | 9.0 | A vulnerability in the internal configuration of the Apache JServ Protocol (AJP) connector for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to impersonate … | Sep 16, 2026 |
| CVE-2026-71182 | LOW | 3.0 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local … | Sep 16, 2026 |
| CVE-2026-71181 | LOW | 3.0 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local … | Sep 16, 2026 |
| CVE-2026-71180 | HIGH | 8.2 | Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this … | Sep 16, 2026 |
| CVE-2026-71179 | HIGH | 7.3 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A … | Sep 16, 2026 |
| CVE-2026-69200 | LOW | 3.7 | node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to node-opcua-client 2.145.0, the internal fieldsToJson method in packages/node-opcua-client/source/alarms_and_conditions/client_alarm.ts directly assigns unsanitized field names … | Sep 16, 2026 |
| CVE-2026-68904 | HIGH | 7.0 | node-opcua is an OPC UA implementation for TypeScript and Node.js. From 2.0.0 until 2.170.0, node-opcua clients using the default keepSessionAlive setting can enter a repeated … | Sep 16, 2026 |
| CVE-2026-59974 | HIGH | 7.8 | Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.14.0, stanza.resources.common.unzip in stanza/resources/common.py passes … | Sep 16, 2026 |