Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57083
Total
4536
Critical
16949
High
16800
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-55630 | NONE | — | Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating … | Sep 15, 2026 |
| CVE-2026-55591 | MEDIUM | 5.8 | Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in src/serverroutes.ts accepted attacker-controlled host, … | Sep 15, 2026 |
| CVE-2026-55211 | CRITICAL | 9.8 | Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to … | Sep 15, 2026 |
| CVE-2026-54724 | MEDIUM | 6.1 | Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker … | Sep 15, 2026 |
| CVE-2026-54450 | UNKNOWN | — | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.29.1, networking.IsPrivateIP in pkg/networking/utilities.go omits the … | Sep 15, 2026 |
| CVE-2026-54077 | HIGH | 7.1 | ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/query/sql/parser/ImportDatabaseStatement.java did not require administrative privileges and passed its source to integration/src/main/java/com/arcadedb/integration/importer/SourceDiscovery.java … | Sep 15, 2026 |
| CVE-2026-54076 | HIGH | 8.1 | ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorization check only to LocalDocumentType.createProperty, while the remaining public schema … | Sep 15, 2026 |
| CVE-2026-50024 | MEDIUM | 5.3 | GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_tasks parses an attacker-controlled ref path from .git/HEAD and … | Sep 15, 2026 |
| CVE-2026-47215 | MEDIUM | 4.8 | SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.4.2 and SingularityPRO 4.3.9 and 4.1.14, incorrect path-string matching in the singularity.conf limit container … | Sep 15, 2026 |
| CVE-2026-44282 | MEDIUM | 4.8 | Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or election editor with question-management rights can store HTML or script-bearing content … | Sep 15, 2026 |
| CVE-2026-44163 | MEDIUM | 5.3 | fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to 0.5.3, the in_opentelemetry HTTP input read the entire incoming request … | Sep 15, 2026 |
| CVE-2026-37152 | UNKNOWN | — | TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access. | Sep 15, 2026 |
| CVE-2026-19407 | UNKNOWN | — | Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) … | Sep 15, 2026 |
| CVE-2024-58384 | MEDIUM | 5.4 | Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can … | Sep 15, 2026 |
| CVE-2024-14029 | HIGH | 7.5 | Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers … | Sep 15, 2026 |
| CVE-2023-54397 | HIGH | 7.5 | Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests … | Sep 15, 2026 |
| CVE-2026-92082 | UNKNOWN | — | By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate … | Sep 15, 2026 |
| CVE-2026-91842 | MEDIUM | 4.1 | A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert of the file obp-api/src/main/scala/code/api/cache/Redis.scala of the component Kryo Handler. … | Sep 15, 2026 |
| CVE-2026-91836 | LOW | 2.8 | A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_scanner.go of the component Static Scanner. … | Sep 15, 2026 |
| CVE-2026-91835 | LOW | 2.8 | A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the file internal/runner/static_scanner.go of the component File … | Sep 15, 2026 |
| CVE-2026-90650 | HIGH | 7.2 | The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook event object 'id' in all versions up to, … | Sep 15, 2026 |
| CVE-2026-90439 | MEDIUM | 6.5 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, … | Sep 15, 2026 |
| CVE-2026-89025 | HIGH | 7.5 | Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker … | Sep 15, 2026 |
| CVE-2026-88618 | MEDIUM | 6.5 | 1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This allows a remote attacker to execute arbitrary code. | Sep 15, 2026 |
| CVE-2026-88617 | UNKNOWN | — | SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to escalate privileges. | Sep 15, 2026 |