Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57083
Total
4536
Critical
16949
High
16800
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-0189 | UNKNOWN | — | In ac_init_policy of init.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of … | Sep 15, 2026 |
| CVE-2026-0187 | UNKNOWN | — | In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation … | Sep 15, 2026 |
| CVE-2026-0186 | UNKNOWN | — | In ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation … | Sep 15, 2026 |
| CVE-2026-0183 | MEDIUM | 4.4 | In CPM, there is a possible information disclosure due to a confused deputy. This could lead to local information disclosure with System execution privileges needed. … | Sep 15, 2026 |
| CVE-2026-0179 | UNKNOWN | — | In Bootloader, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution … | Sep 15, 2026 |
| CVE-2026-0177 | MEDIUM | 4.4 | In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with System … | Sep 15, 2026 |
| CVE-2026-0171 | HIGH | 8.8 | In multiple locations, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with … | Sep 15, 2026 |
| CVE-2026-0170 | HIGH | 8.8 | In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with … | Sep 15, 2026 |
| CVE-2026-0159 | HIGH | 8.8 | In Cellular Modem, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional … | Sep 15, 2026 |
| CVE-2026-88765 | HIGH | 8.5 | GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions … | Sep 15, 2026 |
| CVE-2026-85234 | HIGH | 7.5 | A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a non-empty custom error message, … | Sep 15, 2026 |
| CVE-2026-82837 | MEDIUM | 5.3 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions … | Sep 15, 2026 |
| CVE-2026-81899 | UNKNOWN | — | Concrete CMS 9.0.0 to 9.5.2 stored group folder names without sanitization and printed them unescaped on the Members > Groups dashboard page, resulting in stored … | Sep 15, 2026 |
| CVE-2026-81898 | UNKNOWN | — | In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views. A user able to … | Sep 15, 2026 |
| CVE-2026-81240 | HIGH | 8.6 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could … | Sep 15, 2026 |
| CVE-2026-81239 | HIGH | 8.6 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could … | Sep 15, 2026 |
| CVE-2026-81238 | HIGH | 7.5 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit … | Sep 15, 2026 |
| CVE-2026-81237 | MEDIUM | 6.5 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading … | Sep 15, 2026 |
| CVE-2026-81236 | HIGH | 8.6 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could … | Sep 15, 2026 |
| CVE-2026-81235 | HIGH | 8.0 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability. A high privileged attacker with remote access could potentially exploit this … | Sep 15, 2026 |
| CVE-2026-61668 | HIGH | 8.1 | DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, WorkloadManagementSystem/Utilities/PilotWrapper.py pilotWrapperScript uses ssl._create_unverified_context to download the … | Sep 15, 2026 |
| CVE-2026-61667 | CRITICAL | 9.9 | DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, DataManagementSystem/Service/FileCatalogHandler.py checkDataset forwards an authenticated caller-controlled datasets … | Sep 15, 2026 |
| CVE-2026-58502 | UNKNOWN | — | githubtoplanguages generates a user's top GitHub languages as an SVG. The .github/workflows/discord-issue.yml workflow runs when an issue is opened or closed and interpolates github.event.issue.title directly … | Sep 15, 2026 |
| CVE-2026-58485 | HIGH | 7.1 | mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.7.1, web_url_read receives its caller-controlled … | Sep 15, 2026 |
| CVE-2026-58483 | HIGH | 7.5 | mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.7.1, web_url_read in src/index.ts passes … | Sep 15, 2026 |