Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

57083
Total
4536
Critical
16949
High
16800
Medium
CVE ID Severity Score Description Published
CVE-2026-55630 NONE — Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating … Sep 15, 2026
CVE-2026-55591 MEDIUM 5.8 Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in src/serverroutes.ts accepted attacker-controlled host, … Sep 15, 2026
CVE-2026-55211 CRITICAL 9.8 Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to … Sep 15, 2026
CVE-2026-54724 MEDIUM 6.1 Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker … Sep 15, 2026
CVE-2026-54450 UNKNOWN — ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.29.1, networking.IsPrivateIP in pkg/networking/utilities.go omits the … Sep 15, 2026
CVE-2026-54077 HIGH 7.1 ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/query/sql/parser/ImportDatabaseStatement.java did not require administrative privileges and passed its source to integration/src/main/java/com/arcadedb/integration/importer/SourceDiscovery.java … Sep 15, 2026
CVE-2026-54076 HIGH 8.1 ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorization check only to LocalDocumentType.createProperty, while the remaining public schema … Sep 15, 2026
CVE-2026-50024 MEDIUM 5.3 GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_tasks parses an attacker-controlled ref path from .git/HEAD and … Sep 15, 2026
CVE-2026-47215 MEDIUM 4.8 SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.4.2 and SingularityPRO 4.3.9 and 4.1.14, incorrect path-string matching in the singularity.conf limit container … Sep 15, 2026
CVE-2026-44282 MEDIUM 4.8 Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or election editor with question-management rights can store HTML or script-bearing content … Sep 15, 2026
CVE-2026-44163 MEDIUM 5.3 fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to 0.5.3, the in_opentelemetry HTTP input read the entire incoming request … Sep 15, 2026
CVE-2026-37152 UNKNOWN — TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access. Sep 15, 2026
CVE-2026-19407 UNKNOWN — Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) … Sep 15, 2026
CVE-2024-58384 MEDIUM 5.4 Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can … Sep 15, 2026
CVE-2024-14029 HIGH 7.5 Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers … Sep 15, 2026
CVE-2023-54397 HIGH 7.5 Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests … Sep 15, 2026
CVE-2026-92082 UNKNOWN — By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate … Sep 15, 2026
CVE-2026-91842 MEDIUM 4.1 A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert of the file obp-api/src/main/scala/code/api/cache/Redis.scala of the component Kryo Handler. … Sep 15, 2026
CVE-2026-91836 LOW 2.8 A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_scanner.go of the component Static Scanner. … Sep 15, 2026
CVE-2026-91835 LOW 2.8 A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the file internal/runner/static_scanner.go of the component File … Sep 15, 2026
CVE-2026-90650 HIGH 7.2 The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook event object 'id' in all versions up to, … Sep 15, 2026
CVE-2026-90439 MEDIUM 6.5 NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, … Sep 15, 2026
CVE-2026-89025 HIGH 7.5 Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker … Sep 15, 2026
CVE-2026-88618 MEDIUM 6.5 1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This allows a remote attacker to execute arbitrary code. Sep 15, 2026
CVE-2026-88617 UNKNOWN — SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to escalate privileges. Sep 15, 2026