Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56820
Total
4503
Critical
16867
High
16681
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-77411 | UNKNOWN | — | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLongstr in read.go returns an empty string and a nil error when a declared … | Sep 16, 2026 |
| CVE-2026-77410 | UNKNOWN | — | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.recvContent in channel.go preallocates the message body slice with the uint64 ch.header.Size value supplied … | Sep 16, 2026 |
| CVE-2026-77409 | UNKNOWN | — | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.dispatch in channel.go, confirms.confirm in confirms.go, and Connection.dispatch0 in connection.go synchronously send publisher confirmations, … | Sep 16, 2026 |
| CVE-2026-77408 | UNKNOWN | — | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte length of AMQP shortstr property values … | Sep 16, 2026 |
| CVE-2026-77407 | UNKNOWN | — | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainAuth values defined in auth.go retain passwords as exported plaintext fields in Connection.Config.SASL after … | Sep 16, 2026 |
| CVE-2026-77406 | UNKNOWN | — | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.Qos in channel.go accepts negative prefetchCount and prefetchSize integers and casts them directly to … | Sep 16, 2026 |
| CVE-2026-77405 | UNKNOWN | — | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values without setting MinVersion to tls.VersionTLS12. Builds using a … | Sep 16, 2026 |
| CVE-2026-77404 | UNKNOWN | — | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, URI.String in uri.go concatenates CertFile, KeyFile, CACertFile, and ServerName values directly into an AMQPS … | Sep 16, 2026 |
| CVE-2026-77403 | UNKNOWN | — | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-advertised FrameMax below the AMQP frameMinSize value of 4096 … | Sep 16, 2026 |
| CVE-2026-77401 | MEDIUM | 6.8 | Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Python … | Sep 16, 2026 |
| CVE-2026-77119 | MEDIUM | 5.9 | A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned … | Sep 16, 2026 |
| CVE-2026-76825 | HIGH | 8.4 | RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython … | Sep 16, 2026 |
| CVE-2026-76163 | HIGH | 7.5 | If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may … | Sep 16, 2026 |
| CVE-2026-75029 | MEDIUM | 5.3 | In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If … | Sep 16, 2026 |
| CVE-2026-74909 | HIGH | 8.1 | Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails … | Sep 16, 2026 |
| CVE-2026-63671 | HIGH | 8.1 | MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nuxtjs/mdc uses parseMarkdown with allowDangerousHtml … | Sep 16, 2026 |
| CVE-2026-63128 | HIGH | 7.5 | RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP server in crates/rmcp/src/transport/streamable_http_server/tower.rs allows an … | Sep 16, 2026 |
| CVE-2026-63127 | HIGH | 8.2 | RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 … | Sep 16, 2026 |
| CVE-2026-61709 | MEDIUM | 5.3 | OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded … | Sep 16, 2026 |
| CVE-2026-19668 | MEDIUM | 5.3 | A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on … | Sep 16, 2026 |
| CVE-2026-19666 | HIGH | 7.5 | On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process … | Sep 16, 2026 |
| CVE-2026-19033 | MEDIUM | 6.5 | For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message … | Sep 16, 2026 |
| CVE-2026-18212 | HIGH | 7.5 | A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom … | Sep 16, 2026 |
| CVE-2025-36591 | MEDIUM | 4.4 | Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability. A … | Sep 16, 2026 |
| CVE-2026-92469 | HIGH | 8.1 | zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate … | Sep 16, 2026 |