Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56820
Total
4503
Critical
16867
High
16681
Medium
CVE ID Severity Score Description Published
CVE-2026-77411 UNKNOWN — RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLongstr in read.go returns an empty string and a nil error when a declared … Sep 16, 2026
CVE-2026-77410 UNKNOWN — RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.recvContent in channel.go preallocates the message body slice with the uint64 ch.header.Size value supplied … Sep 16, 2026
CVE-2026-77409 UNKNOWN — RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.dispatch in channel.go, confirms.confirm in confirms.go, and Connection.dispatch0 in connection.go synchronously send publisher confirmations, … Sep 16, 2026
CVE-2026-77408 UNKNOWN — RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte length of AMQP shortstr property values … Sep 16, 2026
CVE-2026-77407 UNKNOWN — RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainAuth values defined in auth.go retain passwords as exported plaintext fields in Connection.Config.SASL after … Sep 16, 2026
CVE-2026-77406 UNKNOWN — RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.Qos in channel.go accepts negative prefetchCount and prefetchSize integers and casts them directly to … Sep 16, 2026
CVE-2026-77405 UNKNOWN — RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values without setting MinVersion to tls.VersionTLS12. Builds using a … Sep 16, 2026
CVE-2026-77404 UNKNOWN — RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, URI.String in uri.go concatenates CertFile, KeyFile, CACertFile, and ServerName values directly into an AMQPS … Sep 16, 2026
CVE-2026-77403 UNKNOWN — RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-advertised FrameMax below the AMQP frameMinSize value of 4096 … Sep 16, 2026
CVE-2026-77401 MEDIUM 6.8 Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Python … Sep 16, 2026
CVE-2026-77119 MEDIUM 5.9 A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned … Sep 16, 2026
CVE-2026-76825 HIGH 8.4 RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython … Sep 16, 2026
CVE-2026-76163 HIGH 7.5 If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may … Sep 16, 2026
CVE-2026-75029 MEDIUM 5.3 In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If … Sep 16, 2026
CVE-2026-74909 HIGH 8.1 Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails … Sep 16, 2026
CVE-2026-63671 HIGH 8.1 MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nuxtjs/mdc uses parseMarkdown with allowDangerousHtml … Sep 16, 2026
CVE-2026-63128 HIGH 7.5 RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP server in crates/rmcp/src/transport/streamable_http_server/tower.rs allows an … Sep 16, 2026
CVE-2026-63127 HIGH 8.2 RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 … Sep 16, 2026
CVE-2026-61709 MEDIUM 5.3 OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded … Sep 16, 2026
CVE-2026-19668 MEDIUM 5.3 A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on … Sep 16, 2026
CVE-2026-19666 HIGH 7.5 On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process … Sep 16, 2026
CVE-2026-19033 MEDIUM 6.5 For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message … Sep 16, 2026
CVE-2026-18212 HIGH 7.5 A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom … Sep 16, 2026
CVE-2025-36591 MEDIUM 4.4 Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability. A … Sep 16, 2026
CVE-2026-92469 HIGH 8.1 zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate … Sep 16, 2026