Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

57048
Total
4535
Critical
16933
High
16775
Medium
CVE ID Severity Score Description Published
CVE-2026-73466 MEDIUM 6.3 On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard … Sep 15, 2026
CVE-2026-73465 MEDIUM 6.3 On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized … Sep 15, 2026
CVE-2026-73451 MEDIUM 4.8 On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting … Sep 15, 2026
CVE-2026-69216 MEDIUM 5.4 Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s chunk decoder trims the chunk-size token and accepts leading plus or … Sep 15, 2026
CVE-2026-69214 MEDIUM 6.8 Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a response cookie’s Domain attribute without checking … Sep 15, 2026
CVE-2026-69213 HIGH 7.5 Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames through one unbounded queue consumed by writeLoop. … Sep 15, 2026
CVE-2026-69212 MEDIUM 5.9 Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The FollowRedirect client middleware strips Authorization and Cookie headers only when a … Sep 15, 2026
CVE-2026-69211 MEDIUM 4.8 Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResponseCookie.render writes attacker-influenced name, content, domain, path, and extension values without neutralizing … Sep 15, 2026
CVE-2026-69209 HIGH 7.5 Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket decoder permits unbounded message buffering because defragmentation accumulates fragments … Sep 15, 2026
CVE-2026-69208 HIGH 7.5 Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, the DigestAuth server middleware removes fresh nonces and stops eviction at the … Sep 15, 2026
CVE-2026-69204 UNKNOWN — Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/1.1 does not reject messages containing both Transfer-Encoding and Content-Length, so … Sep 15, 2026
CVE-2026-69201 MEDIUM 5.9 Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResourceService and WebjarService decode each URL path segment but reject only segments … Sep 15, 2026
CVE-2026-68534 UNKNOWN — Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in stored cross-site scripting. An unauthenticated attacker could submit … Sep 15, 2026
CVE-2026-68533 UNKNOWN — Concrete CMS below 9.5.3 conversation attachment uploaded endpoint imported files into the file manager before evaluating the "Add Message Attachments" permission, which was only checked … Sep 15, 2026
CVE-2026-68532 UNKNOWN — Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery. A remote … Sep 15, 2026
CVE-2026-68531 UNKNOWN — Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard characters in the keyword search filters used by the file manager, file folders, and … Sep 15, 2026
CVE-2026-68530 UNKNOWN — Concrete CMS 9 through 9.5.2 did not perform an authorization check on several board-instance actions in the Boards area of the Dashboard. The instance details … Sep 15, 2026
CVE-2026-68529 UNKNOWN — Concrete CMS 9.0.0 through 9.5.2 was missing an authorization check on the Express entries advanced-search dashboard action. The advanced_search() method in DashboardSelectableExpressEntryListTrait resolved an Express … Sep 15, 2026
CVE-2026-66790 UNKNOWN — Rejected reason: This CVE ID was assigned in error as a duplicate of CVE-2026-70496, which describes the same vulnerability. Please use CVE-2026-70496 instead. Sep 15, 2026
CVE-2026-66789 UNKNOWN — Rejected reason: This CVE ID was assigned in error as a duplicate of CVE-2026-70495, which describes the same vulnerability. Please use CVE-2026-70495 instead. Sep 15, 2026
CVE-2026-58773 MEDIUM 6.7 In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with … Sep 15, 2026
CVE-2026-58767 MEDIUM 6.7 In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local … Sep 15, 2026
CVE-2026-58766 HIGH 7.8 In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local … Sep 15, 2026
CVE-2026-58765 MEDIUM 6.7 In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with … Sep 15, 2026
CVE-2026-58755 MEDIUM 6.7 In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation … Sep 15, 2026