Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

57083
Total
4536
Critical
16949
High
16800
Medium
CVE ID Severity Score Description Published
CVE-2026-0189 UNKNOWN — In ac_init_policy of init.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of … Sep 15, 2026
CVE-2026-0187 UNKNOWN — In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation … Sep 15, 2026
CVE-2026-0186 UNKNOWN — In ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation … Sep 15, 2026
CVE-2026-0183 MEDIUM 4.4 In CPM, there is a possible information disclosure due to a confused deputy. This could lead to local information disclosure with System execution privileges needed. … Sep 15, 2026
CVE-2026-0179 UNKNOWN — In Bootloader, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution … Sep 15, 2026
CVE-2026-0177 MEDIUM 4.4 In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with System … Sep 15, 2026
CVE-2026-0171 HIGH 8.8 In multiple locations, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with … Sep 15, 2026
CVE-2026-0170 HIGH 8.8 In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with … Sep 15, 2026
CVE-2026-0159 HIGH 8.8 In Cellular Modem, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional … Sep 15, 2026
CVE-2026-88765 HIGH 8.5 GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions … Sep 15, 2026
CVE-2026-85234 HIGH 7.5 A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a non-empty custom error message, … Sep 15, 2026
CVE-2026-82837 MEDIUM 5.3 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that certain conditions … Sep 15, 2026
CVE-2026-81899 UNKNOWN — Concrete CMS 9.0.0 to 9.5.2 stored group folder names without sanitization and printed them unescaped on the Members > Groups dashboard page, resulting in stored … Sep 15, 2026
CVE-2026-81898 UNKNOWN — In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling stored XSS in Express association views. A user able to … Sep 15, 2026
CVE-2026-81240 HIGH 8.6 Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could … Sep 15, 2026
CVE-2026-81239 HIGH 8.6 Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could … Sep 15, 2026
CVE-2026-81238 HIGH 7.5 Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit … Sep 15, 2026
CVE-2026-81237 MEDIUM 6.5 Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading … Sep 15, 2026
CVE-2026-81236 HIGH 8.6 Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could … Sep 15, 2026
CVE-2026-81235 HIGH 8.0 Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability. A high privileged attacker with remote access could potentially exploit this … Sep 15, 2026
CVE-2026-61668 HIGH 8.1 DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, WorkloadManagementSystem/Utilities/PilotWrapper.py pilotWrapperScript uses ssl._create_unverified_context to download the … Sep 15, 2026
CVE-2026-61667 CRITICAL 9.9 DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, DataManagementSystem/Service/FileCatalogHandler.py checkDataset forwards an authenticated caller-controlled datasets … Sep 15, 2026
CVE-2026-58502 UNKNOWN — githubtoplanguages generates a user's top GitHub languages as an SVG. The .github/workflows/discord-issue.yml workflow runs when an issue is opened or closed and interpolates github.event.issue.title directly … Sep 15, 2026
CVE-2026-58485 HIGH 7.1 mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.7.1, web_url_read receives its caller-controlled … Sep 15, 2026
CVE-2026-58483 HIGH 7.5 mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.7.1, web_url_read in src/index.ts passes … Sep 15, 2026