Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56820
Total
4503
Critical
16867
High
16681
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-59944 | MEDIUM | 6.1 | Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass … | Sep 16, 2026 |
| CVE-2026-57173 | MEDIUM | 6.5 | vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v1/chat/completions calls AudioMediaIO.load_bytes or AudioMediaIO.load_file without … | Sep 16, 2026 |
| CVE-2026-42784 | HIGH | 7.4 | A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a … | Sep 16, 2026 |
| CVE-2026-20331 | CRITICAL | 9.6 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software … | Sep 16, 2026 |
| CVE-2026-20307 | CRITICAL | 9.9 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system … | Sep 16, 2026 |
| CVE-2026-20306 | CRITICAL | 9.1 | A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying … | Sep 16, 2026 |
| CVE-2026-20305 | CRITICAL | 9.1 | A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying … | Sep 16, 2026 |
| CVE-2026-20234 | CRITICAL | 9.9 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) … | Sep 16, 2026 |
| CVE-2026-92627 | UNKNOWN | — | A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a … | Sep 16, 2026 |
| CVE-2026-92626 | HIGH | 7.5 | Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may … | Sep 16, 2026 |
| CVE-2026-92625 | HIGH | 7.5 | Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/restartService endpoint is reachable without authentication and invokes an … | Sep 16, 2026 |
| CVE-2026-92615 | MEDIUM | 6.6 | A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custom CA bundle, … | Sep 16, 2026 |
| CVE-2026-92397 | CRITICAL | 9.1 | A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. … | Sep 16, 2026 |
| CVE-2026-92385 | LOW | 2.4 | A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_category.php of the … | Sep 16, 2026 |
| CVE-2026-90999 | UNKNOWN | — | Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a … | Sep 16, 2026 |
| CVE-2026-76104 | MEDIUM | 5.5 | Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privileged attacker with remote access … | Sep 16, 2026 |
| CVE-2026-70416 | CRITICAL | 10.0 | Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading … | Sep 16, 2026 |
| CVE-2026-61595 | HIGH | 7.7 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. … | Sep 16, 2026 |
| CVE-2026-61593 | HIGH | 8.1 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the SSE client→server POST endpoints are `@csrf_exempt` and the … | Sep 16, 2026 |
| CVE-2026-26947 | MEDIUM | 6.7 | Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with local … | Sep 16, 2026 |
| CVE-2026-19607 | MEDIUM | 5.3 | A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs … | Sep 16, 2026 |
| CVE-2026-17526 | HIGH | 7.2 | Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. … | Sep 16, 2026 |
| CVE-2025-59953 | CRITICAL | 9.8 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an … | Sep 16, 2026 |
| CVE-2025-43936 | HIGH | 8.1 | Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to … | Sep 16, 2026 |
| CVE-2026-92616 | MEDIUM | 6.8 | FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploiting improper session … | Sep 16, 2026 |