Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57306
Total
4581
Critical
17028
High
16895
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-92012 | HIGH | 8.8 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, … | Sep 15, 2026 |
| CVE-2026-92011 | HIGH | 8.8 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, … | Sep 15, 2026 |
| CVE-2026-92010 | HIGH | 8.8 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, … | Sep 15, 2026 |
| CVE-2026-92009 | HIGH | 8.8 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, … | Sep 15, 2026 |
| CVE-2026-92008 | HIGH | 8.8 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, … | Sep 15, 2026 |
| CVE-2026-92007 | HIGH | 8.8 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, … | Sep 15, 2026 |
| CVE-2026-92006 | HIGH | 8.8 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, … | Sep 15, 2026 |
| CVE-2026-92005 | UNKNOWN | — | Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. | Sep 15, 2026 |
| CVE-2026-15609 | MEDIUM | 6.4 | The Bridge - Creative Multipurpose WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via 'circle_line' Shortcode Attribute in all versions up to, … | Sep 15, 2026 |
| CVE-2026-14805 | HIGH | 8.8 | The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.16. This is due to a combination of two … | Sep 15, 2026 |
| CVE-2026-92003 | UNKNOWN | — | Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model: - … | Sep 15, 2026 |
| CVE-2026-92002 | UNKNOWN | — | Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid excessive duplicate logs while still recording failed authentication … | Sep 15, 2026 |
| CVE-2026-91998 | CRITICAL | 9.9 | Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access … | Sep 15, 2026 |
| CVE-2026-91997 | MEDIUM | 5.3 | evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers … | Sep 15, 2026 |
| CVE-2026-91996 | HIGH | 7.5 | lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map. Attackers can … | Sep 15, 2026 |
| CVE-2026-91995 | CRITICAL | 9.1 | pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. … | Sep 15, 2026 |
| CVE-2026-91994 | MEDIUM | 6.5 | Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or task_runner roles can read all … | Sep 15, 2026 |
| CVE-2026-91993 | MEDIUM | 4.3 | Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoint, allowing authenticated users to access repositories from other workspaces. Attackers … | Sep 15, 2026 |
| CVE-2026-91926 | LOW | 3.7 | A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR … | Sep 15, 2026 |
| CVE-2026-89308 | UNKNOWN | — | An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve … | Sep 15, 2026 |
| CVE-2026-91925 | HIGH | 8.8 | Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run preparation, allowing authenticated users to execute arbitrary code. Attackers can … | Sep 15, 2026 |
| CVE-2026-91924 | HIGH | 8.5 | pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, allowing attackers to supply arbitrary database connection strings. Attackers can bypass … | Sep 15, 2026 |
| CVE-2026-91923 | HIGH | 7.7 | KubeSphere through 4.1.3 contains a server-side request forgery vulnerability in the git credential verification endpoint that accepts unvalidated caller-supplied URLs without allowlist restrictions. Authenticated attackers … | Sep 15, 2026 |
| CVE-2026-91922 | MEDIUM | 6.1 | Steedos Platform through 3.0.15-beta.47 contains a reflected cross-site scripting vulnerability in the anonymous /api/page/render endpoint that fails to properly escape query parameters in inline script … | Sep 15, 2026 |
| CVE-2026-91786 | MEDIUM | 6.1 | A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to validate the icon's declared … | Sep 15, 2026 |