Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56820
Total
4503
Critical
16867
High
16681
Medium
CVE ID Severity Score Description Published
CVE-2026-92571 UNKNOWN — Rejected reason: CVE ID reserved in error and not assigned to a vulnerability. The correct CVE ID is CVE-2026-92574. Sep 16, 2026
CVE-2026-92570 MEDIUM 6.5 reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration files. … Sep 16, 2026
CVE-2026-92569 MEDIUM 4.3 Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that fail to validate the clientAddress parameter. Authenticated attackers can supply arbitrary … Sep 16, 2026
CVE-2026-92568 MEDIUM 5.4 MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary HTTP … Sep 16, 2026
CVE-2026-92567 MEDIUM 6.5 TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form … Sep 16, 2026
CVE-2026-92566 HIGH 8.2 DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying a … Sep 16, 2026
CVE-2026-92565 MEDIUM 5.3 Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers. Attackers … Sep 16, 2026
CVE-2026-92395 CRITICAL 9.1 @fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips. In versions 3.0.0 … Sep 16, 2026
CVE-2026-92383 MEDIUM 4.3 A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserController::del/UserController::mod of the file apps/admin/controller/system/UserController.php of the component User … Sep 16, 2026
CVE-2026-92381 LOW 3.5 A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/controller/content/ContentController.php of the component Template Rendering. This … Sep 16, 2026
CVE-2026-92380 HIGH 7.3 A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreframe/app/attachment/index.php of the component Remote … Sep 16, 2026
CVE-2026-92366 HIGH 7.3 A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search.php of the component Regular Search. This manipulation … Sep 16, 2026
CVE-2026-92087 HIGH 8.1 @fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route guard. In versions 5.0.0 through 5.1.0, when strategies are … Sep 16, 2026
CVE-2026-89031 MEDIUM 5.4 Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in includes/Ajax/Post.php … Sep 16, 2026
CVE-2026-88976 MEDIUM 6.1 Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.0-beta.1 builds, Plate core HTML deserialization APIs … Sep 16, 2026
CVE-2026-88064 HIGH 8.8 Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until 1.15.4, the @backstage/plugin-techdocs-node package insufficiently validates mkdocs.yml supplied by … Sep 16, 2026
CVE-2026-84997 HIGH 7.5 react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a … Sep 16, 2026
CVE-2026-84860 HIGH 8.8 ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints by URL path pattern, but DWR itself dispatches method calls … Sep 16, 2026
CVE-2026-84859 MEDIUM 6.5 ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection The /api/events/search endpoint accepts a JSON body containing a sortBy array. The values … Sep 16, 2026
CVE-2026-84858 HIGH 8.8 ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass The DWR "DataSourceEditDwr" class exposes the "validateScript" method that … Sep 16, 2026
CVE-2026-82964 HIGH 8.8 Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file … Sep 16, 2026
CVE-2026-82410 UNKNOWN — Pocketbase is an open source web backend written in go. Prior to 0.22.48 and 0.39.7, PocketBase's panic-recovery middleware covers regular request handling but not internal … Sep 16, 2026
CVE-2026-80274 HIGH 7.5 If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 … Sep 16, 2026
CVE-2026-79651 HIGH 7.5 A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management … Sep 16, 2026
CVE-2026-77412 UNKNOWN — RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readField in read.go reads the length of an AMQP byte-array field with type tag … Sep 16, 2026