Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56820
Total
4503
Critical
16867
High
16681
Medium
CVE ID Severity Score Description Published
CVE-2026-59944 MEDIUM 6.1 Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass … Sep 16, 2026
CVE-2026-57173 MEDIUM 6.5 vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v1/chat/completions calls AudioMediaIO.load_bytes or AudioMediaIO.load_file without … Sep 16, 2026
CVE-2026-42784 HIGH 7.4 A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a … Sep 16, 2026
CVE-2026-20331 CRITICAL 9.6 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software … Sep 16, 2026
CVE-2026-20307 CRITICAL 9.9 A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system … Sep 16, 2026
CVE-2026-20306 CRITICAL 9.1 A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying … Sep 16, 2026
CVE-2026-20305 CRITICAL 9.1 A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying … Sep 16, 2026
CVE-2026-20234 CRITICAL 9.9 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) … Sep 16, 2026
CVE-2026-92627 UNKNOWN — A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a … Sep 16, 2026
CVE-2026-92626 HIGH 7.5 Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may … Sep 16, 2026
CVE-2026-92625 HIGH 7.5 Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/restartService endpoint is reachable without authentication and invokes an … Sep 16, 2026
CVE-2026-92615 MEDIUM 6.6 A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custom CA bundle, … Sep 16, 2026
CVE-2026-92397 CRITICAL 9.1 A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. … Sep 16, 2026
CVE-2026-92385 LOW 2.4 A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_category.php of the … Sep 16, 2026
CVE-2026-90999 UNKNOWN — Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a … Sep 16, 2026
CVE-2026-76104 MEDIUM 5.5 Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privileged attacker with remote access … Sep 16, 2026
CVE-2026-70416 CRITICAL 10.0 Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading … Sep 16, 2026
CVE-2026-61595 HIGH 7.7 djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. … Sep 16, 2026
CVE-2026-61593 HIGH 8.1 djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the SSE client→server POST endpoints are `@csrf_exempt` and the … Sep 16, 2026
CVE-2026-26947 MEDIUM 6.7 Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with local … Sep 16, 2026
CVE-2026-19607 MEDIUM 5.3 A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs … Sep 16, 2026
CVE-2026-17526 HIGH 7.2 Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. … Sep 16, 2026
CVE-2025-59953 CRITICAL 9.8 LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an … Sep 16, 2026
CVE-2025-43936 HIGH 8.1 Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to … Sep 16, 2026
CVE-2026-92616 MEDIUM 6.8 FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploiting improper session … Sep 16, 2026