Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

57327
Total
4582
Critical
17032
High
16910
Medium
CVE ID Severity Score Description Published
CVE-2026-91199 MEDIUM 5.0 Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches caller-supplied URLs without validating the scheme, host, or resolved … Sep 14, 2026
CVE-2026-91198 MEDIUM 5.3 GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge … Sep 14, 2026
CVE-2026-91197 MEDIUM 6.5 Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resources. … Sep 14, 2026
CVE-2026-90835 LOW 3.5 A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the file Markdown.java of the component … Sep 14, 2026
CVE-2026-90831 MEDIUM 5.3 A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. … Sep 14, 2026
CVE-2026-90830 MEDIUM 5.3 A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The … Sep 14, 2026
CVE-2026-90829 MEDIUM 5.3 A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. … Sep 14, 2026
CVE-2026-81900 UNKNOWN — Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them into iframe HTML attributes without escaping … Sep 14, 2026
CVE-2026-77191 LOW 2.6 An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between … Sep 14, 2026
CVE-2026-75945 LOW 2.6 A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued. Sep 14, 2026
CVE-2026-75944 LOW 2.6 A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry … Sep 14, 2026
CVE-2026-75943 LOW 2.6 A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or … Sep 14, 2026
CVE-2026-18116 UNKNOWN — Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in the workflow approval and deletion notifications shown … Sep 14, 2026
CVE-2026-14986 MEDIUM 6.8 The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGET_BUFFER_MODE), copies host-supplied write data into the fixed-size … Sep 14, 2026
CVE-2026-91181 MEDIUM 6.5 Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams … Sep 14, 2026
CVE-2026-91146 MEDIUM 6.1 Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links. … Sep 14, 2026
CVE-2026-91145 HIGH 7.1 Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{ … Sep 14, 2026
CVE-2026-91144 HIGH 7.5 ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can … Sep 14, 2026
CVE-2026-91143 HIGH 7.2 goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT … Sep 14, 2026
CVE-2026-90828 MEDIUM 5.3 A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan … Sep 14, 2026
CVE-2026-90827 LOW 3.3 A vulnerability was identified in GPAC 26.07.0. This affects the function gf_node_deactivate_ex of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use … Sep 14, 2026
CVE-2026-90826 LOW 2.8 A vulnerability was determined in GPAC 26.07.0. Affected by this issue is the function gf_node_del of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation … Sep 14, 2026
CVE-2026-90825 LOW 3.3 A vulnerability was found in GPAC 26.07.0. Affected by this vulnerability is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation … Sep 14, 2026
CVE-2026-76081 MEDIUM 5.5 ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permissions when multiple project roles are deleted … Sep 14, 2026
CVE-2026-73449 MEDIUM 5.9 On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an … Sep 14, 2026