Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57083
Total
4536
Critical
16949
High
16800
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-48722 | MEDIUM | 5.5 | Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth login writes Seqera Platform OIDC bearer tokens to ${NXF_HOME:-~/.nextflow}/seqera-auth.config … | Sep 15, 2026 |
| CVE-2026-47780 | UNKNOWN | — | free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and HandleQueryeesubscriptions in free5gc/udr internal/sbi/api_datarepository.go validate the ueId path value … | Sep 15, 2026 |
| CVE-2026-46495 | UNKNOWN | — | OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/java/org/opends/server/protocols/jmx/RmiConnector.java processes attacker-controlled credential objects before authentication without a restrictive … | Sep 15, 2026 |
| CVE-2026-39919 | CRITICAL | 9.8 | Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying … | Sep 15, 2026 |
| CVE-2026-25827 | UNKNOWN | — | An issue was discovered in Keyfactor SignServer before 7.6.0. A number of properties were identified to not have any restrictions to what path they can … | Sep 15, 2026 |
| CVE-2026-25826 | UNKNOWN | — | An issue was discovered in Keyfactor SignServer before 7.6.0. The attribute ATTRIBUTESFILE in PKCS11CryptoToken can be set to a readable file but not an accepted … | Sep 15, 2026 |
| CVE-2026-25825 | UNKNOWN | — | An issue was discovered in Keyfactor SignServer before 7.6.0. The output file to which SignerStatusReportWorker logs the report can be set to any path, even … | Sep 15, 2026 |
| CVE-2026-77179 | UNKNOWN | — | On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest … | Sep 15, 2026 |
| CVE-2026-16141 | HIGH | 8.1 | OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites … | Sep 15, 2026 |
| CVE-2026-16140 | HIGH | 8.8 | OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account … | Sep 15, 2026 |
| CVE-2026-92079 | UNKNOWN | — | Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92078 | UNKNOWN | — | Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92077 | UNKNOWN | — | Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92076 | UNKNOWN | — | Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92075 | UNKNOWN | — | Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92074 | UNKNOWN | — | Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92073 | HIGH | 8.8 | Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92072 | UNKNOWN | — | Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92071 | UNKNOWN | — | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92070 | UNKNOWN | — | Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92069 | UNKNOWN | — | Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92068 | UNKNOWN | — | Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92067 | UNKNOWN | — | Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92066 | UNKNOWN | — | Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | Sep 15, 2026 |
| CVE-2026-92065 | UNKNOWN | — | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. | Sep 15, 2026 |