Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57306
Total
4581
Critical
17028
High
16895
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-90841 | HIGH | 7.3 | A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php … | Sep 15, 2026 |
| CVE-2026-90840 | HIGH | 7.3 | A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of the file /application/controllers/admin/Dashboard.php of the component Admin Controllers. … | Sep 15, 2026 |
| CVE-2026-91201 | MEDIUM | 5.4 | DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session … | Sep 14, 2026 |
| CVE-2026-91200 | HIGH | 8.8 | DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar … | Sep 14, 2026 |
| CVE-2026-91199 | MEDIUM | 5.0 | Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches caller-supplied URLs without validating the scheme, host, or resolved … | Sep 14, 2026 |
| CVE-2026-91198 | MEDIUM | 5.3 | GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge … | Sep 14, 2026 |
| CVE-2026-91197 | MEDIUM | 6.5 | Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resources. … | Sep 14, 2026 |
| CVE-2026-90835 | LOW | 3.5 | A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the file Markdown.java of the component … | Sep 14, 2026 |
| CVE-2026-90831 | MEDIUM | 5.3 | A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. … | Sep 14, 2026 |
| CVE-2026-90830 | MEDIUM | 5.3 | A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The … | Sep 14, 2026 |
| CVE-2026-90829 | MEDIUM | 5.3 | A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. … | Sep 14, 2026 |
| CVE-2026-81900 | UNKNOWN | — | Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them into iframe HTML attributes without escaping … | Sep 14, 2026 |
| CVE-2026-77191 | LOW | 2.6 | An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between … | Sep 14, 2026 |
| CVE-2026-75945 | LOW | 2.6 | A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued. | Sep 14, 2026 |
| CVE-2026-75944 | LOW | 2.6 | A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry … | Sep 14, 2026 |
| CVE-2026-75943 | LOW | 2.6 | A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or … | Sep 14, 2026 |
| CVE-2026-18116 | UNKNOWN | — | Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in the workflow approval and deletion notifications shown … | Sep 14, 2026 |
| CVE-2026-14986 | MEDIUM | 6.8 | The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGET_BUFFER_MODE), copies host-supplied write data into the fixed-size … | Sep 14, 2026 |
| CVE-2026-91181 | MEDIUM | 6.5 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams … | Sep 14, 2026 |
| CVE-2026-91146 | MEDIUM | 6.1 | Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links. … | Sep 14, 2026 |
| CVE-2026-91145 | HIGH | 7.1 | Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{ … | Sep 14, 2026 |
| CVE-2026-91144 | HIGH | 7.5 | ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can … | Sep 14, 2026 |
| CVE-2026-91143 | HIGH | 7.2 | goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT … | Sep 14, 2026 |
| CVE-2026-90828 | MEDIUM | 5.3 | A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan … | Sep 14, 2026 |
| CVE-2026-90827 | LOW | 3.3 | A vulnerability was identified in GPAC 26.07.0. This affects the function gf_node_deactivate_ex of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use … | Sep 14, 2026 |