Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57306
Total
4581
Critical
17028
High
16895
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-5802 | MEDIUM | 5.3 | The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing … | Sep 15, 2026 |
| CVE-2025-13166 | LOW | 3.7 | The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses … | Sep 15, 2026 |
| CVE-2026-91851 | UNKNOWN | — | Affected versions of MISP incorrectly filter dashboard templates that are restricted to a specific permission flag. DashboardsController::listTemplates() allowed a template when either: - its restrict_to_permission_flag … | Sep 15, 2026 |
| CVE-2026-91846 | UNKNOWN | — | Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whether the acting user is allowed to … | Sep 15, 2026 |
| CVE-2026-91826 | MEDIUM | 4.4 | Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects … | Sep 15, 2026 |
| CVE-2026-91825 | UNKNOWN | — | Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable logic checked whether the acting user could … | Sep 15, 2026 |
| CVE-2026-91782 | LOW | 3.3 | A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation … | Sep 15, 2026 |
| CVE-2026-91781 | LOW | 3.3 | A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. … | Sep 15, 2026 |
| CVE-2026-91780 | LOW | 3.3 | A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null … | Sep 15, 2026 |
| CVE-2026-91779 | LOW | 3.3 | A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. … | Sep 15, 2026 |
| CVE-2026-87730 | UNKNOWN | — | Rejected reason: this is rejected | Sep 15, 2026 |
| CVE-2026-80217 | HIGH | 8.8 | Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on … | Sep 15, 2026 |
| CVE-2026-77853 | HIGH | 8.8 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in … | Sep 15, 2026 |
| CVE-2026-76159 | UNKNOWN | — | Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows versions before v2.4.0.0 allows a local low-privileged attacker to escalate privileges … | Sep 15, 2026 |
| CVE-2026-75092 | HIGH | 7.3 | A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: … | Sep 15, 2026 |
| CVE-2026-91819 | UNKNOWN | — | Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field … | Sep 15, 2026 |
| CVE-2026-91778 | UNKNOWN | — | In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). … | Sep 15, 2026 |
| CVE-2026-91091 | MEDIUM | 4.3 | A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. … | Sep 15, 2026 |
| CVE-2026-91090 | LOW | 3.9 | A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the file scenegraph/base_scenegraph.c. This manipulation causes stack-based buffer … | Sep 15, 2026 |
| CVE-2026-91089 | MEDIUM | 6.3 | A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegraph/base_scenegraph.c. The manipulation results in use after free. … | Sep 15, 2026 |
| CVE-2026-91088 | MEDIUM | 4.8 | A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file utils/url.c of the component URL Handler. … | Sep 15, 2026 |
| CVE-2026-91087 | HIGH | 7.3 | A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c of the component Compositor. Executing … | Sep 15, 2026 |
| CVE-2026-91086 | MEDIUM | 6.3 | A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_process of the file filters/reframe_mpgvid.c of the … | Sep 15, 2026 |
| CVE-2026-91005 | MEDIUM | 6.3 | A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file production/edit_picture.php of the component Profile Picture … | Sep 15, 2026 |
| CVE-2026-90711 | CRITICAL | 9.1 | proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 … | Sep 15, 2026 |