Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57327
Total
4582
Critical
17032
High
16910
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-84505 | HIGH | 7.8 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. … | Sep 14, 2026 |
| CVE-2026-84497 | UNKNOWN | — | A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS … | Sep 14, 2026 |
| CVE-2026-84492 | MEDIUM | 4.7 | A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS … | Sep 14, 2026 |
| CVE-2026-84491 | UNKNOWN | — | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden … | Sep 14, 2026 |
| CVE-2026-84489 | MEDIUM | 5.5 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS … | Sep 14, 2026 |
| CVE-2026-84487 | UNKNOWN | — | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS … | Sep 14, 2026 |
| CVE-2026-81903 | UNKNOWN | — | Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon value submitted through the dashboard without validating it against the set of known container … | Sep 14, 2026 |
| CVE-2026-81902 | UNKNOWN | — | Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block removal panel action (removeOrphanedBlocks). A remote attacker could craft a … | Sep 14, 2026 |
| CVE-2026-81901 | UNKNOWN | — | In Concrete CMS 9.2.0 through 9.5.2, the REST API page update endpoint (PUT /ccm/api/1.0/pages/{cID}) did not enforce page-property, page-template, or page-type authorization. A user granted … | Sep 14, 2026 |
| CVE-2026-7884 | MEDIUM | 5.4 | IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit their given name and surname to include … | Sep 14, 2026 |
| CVE-2026-78415 | MEDIUM | 5.4 | IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to perform UI spoofing and phishing attacks due to improper neutralization of … | Sep 14, 2026 |
| CVE-2026-75792 | MEDIUM | 4.3 | IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to view administrative user interface components due to client-side authorization bypass. | Sep 14, 2026 |
| CVE-2026-68489 | UNKNOWN | — | Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticated users to execute arbitrary code as root via … | Sep 14, 2026 |
| CVE-2026-67399 | UNKNOWN | — | Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code. | Sep 14, 2026 |
| CVE-2026-65415 | HIGH | 8.1 | A race condition was addressed with additional validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS … | Sep 14, 2026 |
| CVE-2026-65414 | CRITICAL | 9.8 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, … | Sep 14, 2026 |
| CVE-2026-65413 | UNKNOWN | — | An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An … | Sep 14, 2026 |
| CVE-2026-65412 | UNKNOWN | — | A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, … | Sep 14, 2026 |
| CVE-2026-65411 | UNKNOWN | — | A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, visionOS … | Sep 14, 2026 |
| CVE-2026-65410 | UNKNOWN | — | The issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate … | Sep 14, 2026 |
| CVE-2026-65409 | UNKNOWN | — | A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, … | Sep 14, 2026 |
| CVE-2026-65408 | UNKNOWN | — | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS … | Sep 14, 2026 |
| CVE-2026-65407 | UNKNOWN | — | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, iOS 26.7 and iPadOS … | Sep 14, 2026 |
| CVE-2026-65406 | UNKNOWN | — | A logic issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden … | Sep 14, 2026 |
| CVE-2026-65405 | UNKNOWN | — | A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, … | Sep 14, 2026 |