Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57327
Total
4582
Critical
17032
High
16910
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-91199 | MEDIUM | 5.0 | Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches caller-supplied URLs without validating the scheme, host, or resolved … | Sep 14, 2026 |
| CVE-2026-91198 | MEDIUM | 5.3 | GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge … | Sep 14, 2026 |
| CVE-2026-91197 | MEDIUM | 6.5 | Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resources. … | Sep 14, 2026 |
| CVE-2026-90835 | LOW | 3.5 | A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the file Markdown.java of the component … | Sep 14, 2026 |
| CVE-2026-90831 | MEDIUM | 5.3 | A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. … | Sep 14, 2026 |
| CVE-2026-90830 | MEDIUM | 5.3 | A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The … | Sep 14, 2026 |
| CVE-2026-90829 | MEDIUM | 5.3 | A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. … | Sep 14, 2026 |
| CVE-2026-81900 | UNKNOWN | — | Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them into iframe HTML attributes without escaping … | Sep 14, 2026 |
| CVE-2026-77191 | LOW | 2.6 | An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between … | Sep 14, 2026 |
| CVE-2026-75945 | LOW | 2.6 | A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued. | Sep 14, 2026 |
| CVE-2026-75944 | LOW | 2.6 | A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry … | Sep 14, 2026 |
| CVE-2026-75943 | LOW | 2.6 | A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or … | Sep 14, 2026 |
| CVE-2026-18116 | UNKNOWN | — | Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in the workflow approval and deletion notifications shown … | Sep 14, 2026 |
| CVE-2026-14986 | MEDIUM | 6.8 | The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGET_BUFFER_MODE), copies host-supplied write data into the fixed-size … | Sep 14, 2026 |
| CVE-2026-91181 | MEDIUM | 6.5 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams … | Sep 14, 2026 |
| CVE-2026-91146 | MEDIUM | 6.1 | Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links. … | Sep 14, 2026 |
| CVE-2026-91145 | HIGH | 7.1 | Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{ … | Sep 14, 2026 |
| CVE-2026-91144 | HIGH | 7.5 | ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can … | Sep 14, 2026 |
| CVE-2026-91143 | HIGH | 7.2 | goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT … | Sep 14, 2026 |
| CVE-2026-90828 | MEDIUM | 5.3 | A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan … | Sep 14, 2026 |
| CVE-2026-90827 | LOW | 3.3 | A vulnerability was identified in GPAC 26.07.0. This affects the function gf_node_deactivate_ex of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use … | Sep 14, 2026 |
| CVE-2026-90826 | LOW | 2.8 | A vulnerability was determined in GPAC 26.07.0. Affected by this issue is the function gf_node_del of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation … | Sep 14, 2026 |
| CVE-2026-90825 | LOW | 3.3 | A vulnerability was found in GPAC 26.07.0. Affected by this vulnerability is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation … | Sep 14, 2026 |
| CVE-2026-76081 | MEDIUM | 5.5 | ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permissions when multiple project roles are deleted … | Sep 14, 2026 |
| CVE-2026-73449 | MEDIUM | 5.9 | On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an … | Sep 14, 2026 |