Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56907
Total
4512
Critical
16897
High
16715
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-86465 | UNKNOWN | — | Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped … | Sep 16, 2026 |
| CVE-2026-86462 | UNKNOWN | — | Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who … | Sep 16, 2026 |
| CVE-2026-86338 | UNKNOWN | — | Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may not see is referenced in a filter, it is … | Sep 16, 2026 |
| CVE-2026-85501 | MEDIUM | 5.3 | Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones … | Sep 16, 2026 |
| CVE-2026-82720 | MEDIUM | 5.9 | NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., … | Sep 16, 2026 |
| CVE-2026-82717 | UNKNOWN | — | In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and … | Sep 16, 2026 |
| CVE-2026-82311 | UNKNOWN | — | Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented behaviour that it does. The cleanup compares … | Sep 16, 2026 |
| CVE-2026-81642 | UNKNOWN | — | In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote … | Sep 16, 2026 |
| CVE-2026-81634 | HIGH | 7.5 | In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer … | Sep 16, 2026 |
| CVE-2026-80225 | MEDIUM | 5.3 | In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit … | Sep 16, 2026 |
| CVE-2026-78227 | MEDIUM | 6.5 | NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'. Each DoQ stream owns an … | Sep 16, 2026 |
| CVE-2026-77955 | MEDIUM | 4.4 | In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) … | Sep 16, 2026 |
| CVE-2026-77860 | LOW | 3.7 | In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a double decrement on the 'wait-limit' counter … | Sep 16, 2026 |
| CVE-2026-73464 | HIGH | 8.8 | On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted request could allow a malicious authenticated client with gRPC … | Sep 16, 2026 |
| CVE-2026-73463 | MEDIUM | 5.3 | On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may … | Sep 16, 2026 |
| CVE-2026-73461 | HIGH | 8.0 | On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, … | Sep 16, 2026 |
| CVE-2026-73454 | HIGH | 8.1 | On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target … | Sep 16, 2026 |
| CVE-2026-73445 | MEDIUM | 4.9 | On affected platforms running Arista EOS, an issue with the gRPC Network Security Interface (gNSI) Authz Rotate RPC may cause an incorrect Authz policy which … | Sep 16, 2026 |
| CVE-2026-73439 | HIGH | 7.5 | On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is configured and … | Sep 16, 2026 |
| CVE-2026-2380 | HIGH | 7.4 | On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged. These may … | Sep 16, 2026 |
| CVE-2026-92355 | UNKNOWN | — | In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a path traversal flaw to overwrite arbitrary … | Sep 16, 2026 |
| CVE-2026-92091 | MEDIUM | 5.9 | A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexity, and … | Sep 16, 2026 |
| CVE-2026-89207 | MEDIUM | 6.5 | A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (All versions < V4.17). Affected devices do not properly … | Sep 16, 2026 |
| CVE-2026-88263 | HIGH | 7.5 | XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve the configuration data containing network configurations and passwords to operate the affected … | Sep 16, 2026 |
| CVE-2026-86341 | MEDIUM | 4.4 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain … | Sep 16, 2026 |