Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57048
Total
4535
Critical
16933
High
16775
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-73466 | MEDIUM | 6.3 | On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard … | Sep 15, 2026 |
| CVE-2026-73465 | MEDIUM | 6.3 | On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized … | Sep 15, 2026 |
| CVE-2026-73451 | MEDIUM | 4.8 | On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting … | Sep 15, 2026 |
| CVE-2026-69216 | MEDIUM | 5.4 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s chunk decoder trims the chunk-size token and accepts leading plus or … | Sep 15, 2026 |
| CVE-2026-69214 | MEDIUM | 6.8 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a response cookie’s Domain attribute without checking … | Sep 15, 2026 |
| CVE-2026-69213 | HIGH | 7.5 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames through one unbounded queue consumed by writeLoop. … | Sep 15, 2026 |
| CVE-2026-69212 | MEDIUM | 5.9 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The FollowRedirect client middleware strips Authorization and Cookie headers only when a … | Sep 15, 2026 |
| CVE-2026-69211 | MEDIUM | 4.8 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResponseCookie.render writes attacker-influenced name, content, domain, path, and extension values without neutralizing … | Sep 15, 2026 |
| CVE-2026-69209 | HIGH | 7.5 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket decoder permits unbounded message buffering because defragmentation accumulates fragments … | Sep 15, 2026 |
| CVE-2026-69208 | HIGH | 7.5 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, the DigestAuth server middleware removes fresh nonces and stops eviction at the … | Sep 15, 2026 |
| CVE-2026-69204 | UNKNOWN | — | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/1.1 does not reject messages containing both Transfer-Encoding and Content-Length, so … | Sep 15, 2026 |
| CVE-2026-69201 | MEDIUM | 5.9 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResourceService and WebjarService decode each URL path segment but reject only segments … | Sep 15, 2026 |
| CVE-2026-68534 | UNKNOWN | — | Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in stored cross-site scripting. An unauthenticated attacker could submit … | Sep 15, 2026 |
| CVE-2026-68533 | UNKNOWN | — | Concrete CMS below 9.5.3 conversation attachment uploaded endpoint imported files into the file manager before evaluating the "Add Message Attachments" permission, which was only checked … | Sep 15, 2026 |
| CVE-2026-68532 | UNKNOWN | — | Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery. A remote … | Sep 15, 2026 |
| CVE-2026-68531 | UNKNOWN | — | Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard characters in the keyword search filters used by the file manager, file folders, and … | Sep 15, 2026 |
| CVE-2026-68530 | UNKNOWN | — | Concrete CMS 9 through 9.5.2 did not perform an authorization check on several board-instance actions in the Boards area of the Dashboard. The instance details … | Sep 15, 2026 |
| CVE-2026-68529 | UNKNOWN | — | Concrete CMS 9.0.0 through 9.5.2 was missing an authorization check on the Express entries advanced-search dashboard action. The advanced_search() method in DashboardSelectableExpressEntryListTrait resolved an Express … | Sep 15, 2026 |
| CVE-2026-66790 | UNKNOWN | — | Rejected reason: This CVE ID was assigned in error as a duplicate of CVE-2026-70496, which describes the same vulnerability. Please use CVE-2026-70496 instead. | Sep 15, 2026 |
| CVE-2026-66789 | UNKNOWN | — | Rejected reason: This CVE ID was assigned in error as a duplicate of CVE-2026-70495, which describes the same vulnerability. Please use CVE-2026-70495 instead. | Sep 15, 2026 |
| CVE-2026-58773 | MEDIUM | 6.7 | In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with … | Sep 15, 2026 |
| CVE-2026-58767 | MEDIUM | 6.7 | In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local … | Sep 15, 2026 |
| CVE-2026-58766 | HIGH | 7.8 | In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local … | Sep 15, 2026 |
| CVE-2026-58765 | MEDIUM | 6.7 | In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with … | Sep 15, 2026 |
| CVE-2026-58755 | MEDIUM | 6.7 | In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation … | Sep 15, 2026 |