Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56907
Total
4512
Critical
16897
High
16715
Medium
CVE ID Severity Score Description Published
CVE-2026-86465 UNKNOWN — Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped … Sep 16, 2026
CVE-2026-86462 UNKNOWN — Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who … Sep 16, 2026
CVE-2026-86338 UNKNOWN — Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may not see is referenced in a filter, it is … Sep 16, 2026
CVE-2026-85501 MEDIUM 5.3 Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones … Sep 16, 2026
CVE-2026-82720 MEDIUM 5.9 NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., … Sep 16, 2026
CVE-2026-82717 UNKNOWN — In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and … Sep 16, 2026
CVE-2026-82311 UNKNOWN — Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented behaviour that it does. The cleanup compares … Sep 16, 2026
CVE-2026-81642 UNKNOWN — In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote … Sep 16, 2026
CVE-2026-81634 HIGH 7.5 In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer … Sep 16, 2026
CVE-2026-80225 MEDIUM 5.3 In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit … Sep 16, 2026
CVE-2026-78227 MEDIUM 6.5 NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'. Each DoQ stream owns an … Sep 16, 2026
CVE-2026-77955 MEDIUM 4.4 In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) … Sep 16, 2026
CVE-2026-77860 LOW 3.7 In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a double decrement on the 'wait-limit' counter … Sep 16, 2026
CVE-2026-73464 HIGH 8.8 On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted request could allow a malicious authenticated client with gRPC … Sep 16, 2026
CVE-2026-73463 MEDIUM 5.3 On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may … Sep 16, 2026
CVE-2026-73461 HIGH 8.0 On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, … Sep 16, 2026
CVE-2026-73454 HIGH 8.1 On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target … Sep 16, 2026
CVE-2026-73445 MEDIUM 4.9 On affected platforms running Arista EOS, an issue with the gRPC Network Security Interface (gNSI) Authz Rotate RPC may cause an incorrect Authz policy which … Sep 16, 2026
CVE-2026-73439 HIGH 7.5 On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is configured and … Sep 16, 2026
CVE-2026-2380 HIGH 7.4 On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged. These may … Sep 16, 2026
CVE-2026-92355 UNKNOWN — In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary … Sep 16, 2026
CVE-2026-92091 MEDIUM 5.9 A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexity, and … Sep 16, 2026
CVE-2026-89207 MEDIUM 6.5 A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (All versions < V4.17). Affected devices do not properly … Sep 16, 2026
CVE-2026-88263 HIGH 7.5 XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected … Sep 16, 2026
CVE-2026-86341 MEDIUM 4.4 GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain … Sep 16, 2026