Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57306
Total
4581
Critical
17028
High
16895
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-90855 | HIGH | 7.3 | A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This affects an unknown function of the file /web/order.php. This manipulation of the … | Sep 15, 2026 |
| CVE-2026-90854 | HIGH | 7.3 | A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element is an unknown function of the file /web/category-foods.php. The … | Sep 15, 2026 |
| CVE-2026-90852 | HIGH | 7.3 | A vulnerability has been found in luben zstd-jni up to 1.5.7-13. This vulnerability affects the function ZstdCompressCtx.loadDict of the file ZstdCompressCtx.java of the component Dictionary … | Sep 15, 2026 |
| CVE-2026-88262 | UNKNOWN | — | Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass. This issue affects xClick: R2, R3, and R3.1. | Sep 15, 2026 |
| CVE-2026-88261 | UNKNOWN | — | Improper input validation vulnerability in bizwell xClick allows Stored XSS. This issue affects xClick: R2, R3, and R3.1. | Sep 15, 2026 |
| CVE-2026-91774 | MEDIUM | 4.3 | Yao through v1.0.0-rc22 authenticates but fails to authorize the GET /user/teams/:id endpoint, allowing any logged-in user to read full team records. Attackers can supply a … | Sep 15, 2026 |
| CVE-2026-91773 | MEDIUM | 4.3 | Soft Serve versions 0.7.1 through 0.11.6 fail to scope Git LFS lock queries by repository, allowing authenticated users to read lock metadata from repositories they … | Sep 15, 2026 |
| CVE-2026-91772 | MEDIUM | 6.1 | Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to validate the uri query parameter. Attackers can craft malicious … | Sep 15, 2026 |
| CVE-2026-91771 | HIGH | 8.8 | Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling … | Sep 15, 2026 |
| CVE-2026-91770 | MEDIUM | 6.5 | IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records. Attackers can substitute … | Sep 15, 2026 |
| CVE-2026-90851 | MEDIUM | 6.3 | A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includes/checklogin.php. This manipulation of the argument … | Sep 15, 2026 |
| CVE-2026-90850 | LOW | 2.4 | A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown functionality of the file /admin/manage-students.php. The manipulation results … | Sep 15, 2026 |
| CVE-2026-90849 | HIGH | 7.3 | A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. Affected by this vulnerability is an unknown functionality of the file … | Sep 15, 2026 |
| CVE-2026-90848 | MEDIUM | 4.3 | A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of … | Sep 15, 2026 |
| CVE-2026-91752 | HIGH | 7.5 | GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. … | Sep 15, 2026 |
| CVE-2026-91751 | HIGH | 8.3 | Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or … | Sep 15, 2026 |
| CVE-2026-91750 | MEDIUM | 6.5 | WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs. Authenticated attackers can bypass initial … | Sep 15, 2026 |
| CVE-2026-90847 | CRITICAL | 9.1 | A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. … | Sep 15, 2026 |
| CVE-2026-90846 | HIGH | 7.3 | A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the … | Sep 15, 2026 |
| CVE-2026-90845 | LOW | 3.5 | A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the file /dets/includes/sidebar.php. Executing a manipulation … | Sep 15, 2026 |
| CVE-2026-90844 | HIGH | 7.3 | A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /dets/index.php of the component Login. Performing … | Sep 15, 2026 |
| CVE-2026-90843 | HIGH | 8.3 | A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmap_newscan of the file functions_nmap.py of the component New … | Sep 15, 2026 |
| CVE-2026-85657 | MEDIUM | 5.4 | The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … | Sep 15, 2026 |
| CVE-2026-85575 | MEDIUM | 6.4 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored … | Sep 15, 2026 |
| CVE-2026-90842 | LOW | 3.7 | A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/models/admin/Login_Model.php. This … | Sep 15, 2026 |