Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56820
Total
4503
Critical
16867
High
16681
Medium
CVE ID Severity Score Description Published
CVE-2026-92601 MEDIUM 6.5 Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission defaults to false and is not overridden by any action methods. Authenticated … Sep 16, 2026
CVE-2026-92600 MEDIUM 6.5 Guns through 8.3.5 contains an information disclosure vulnerability in SysUserController where /sysUser/detail and /sysUser/page endpoints omit requiredPermission configuration, causing the permission interceptor to skip RBAC … Sep 16, 2026
CVE-2026-92405 HIGH 7.3 A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element is an unknown function of the file /index.php. Such … Sep 16, 2026
CVE-2026-92402 MEDIUM 6.3 A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affects the function index of the file UserController.java of the component … Sep 16, 2026
CVE-2026-92401 HIGH 7.3 A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects the function top.upstudy.crm.utils.LoginUserUtil.releaseUserIdFromCookie. The manipulation leads to improper authentication. The attack can … Sep 16, 2026
CVE-2026-92399 HIGH 7.3 A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utils/rmt_ws.c of the component WebSocket Handler. Executing a manipulation of … Sep 16, 2026
CVE-2026-92398 CRITICAL 9.1 A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admin of the component user_list_note Module. … Sep 16, 2026
CVE-2026-87031 UNKNOWN — n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of concrete/src/Api/Controller/Users.php) did not perform a permission check … Sep 16, 2026
CVE-2026-87028 UNKNOWN — Concrete CMS 9 through 9.5.3 did not confirm that a board InstanceItem submitted to the custom-slot preview endpoint belonged to the board instance the requesting … Sep 16, 2026
CVE-2026-86359 HIGH 8.5 Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, … Sep 16, 2026
CVE-2026-86358 MEDIUM 6.5 Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this … Sep 16, 2026
CVE-2026-85756 HIGH 7.5 SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into the command used to run scp on … Sep 16, 2026
CVE-2026-85732 MEDIUM 4.7 oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link … Sep 16, 2026
CVE-2026-85731 HIGH 8.8 oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store … Sep 16, 2026
CVE-2026-85386 UNKNOWN — Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload question. Plain XML uploads were validated by … Sep 16, 2026
CVE-2026-85385 UNKNOWN — Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output encoding on the Dashboard user management … Sep 16, 2026
CVE-2026-84993 MEDIUM 6.5 MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to 6.6.16 and 7.1.7, the shared … Sep 16, 2026
CVE-2026-76420 CRITICAL 9.0 A vulnerability in the internal configuration of the Apache JServ Protocol (AJP) connector for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to impersonate … Sep 16, 2026
CVE-2026-71182 LOW 3.0 Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local … Sep 16, 2026
CVE-2026-71181 LOW 3.0 Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local … Sep 16, 2026
CVE-2026-71180 HIGH 8.2 Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this … Sep 16, 2026
CVE-2026-71179 HIGH 7.3 Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A … Sep 16, 2026
CVE-2026-69200 LOW 3.7 node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to node-opcua-client 2.145.0, the internal fieldsToJson method in packages/node-opcua-client/source/alarms_and_conditions/client_alarm.ts directly assigns unsanitized field names … Sep 16, 2026
CVE-2026-68904 HIGH 7.0 node-opcua is an OPC UA implementation for TypeScript and Node.js. From 2.0.0 until 2.170.0, node-opcua clients using the default keepSessionAlive setting can enter a repeated … Sep 16, 2026
CVE-2026-59974 HIGH 7.8 Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.14.0, stanza.resources.common.unzip in stanza/resources/common.py passes … Sep 16, 2026