Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57401
Total
4583
Critical
17032
High
16919
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-55093 | MEDIUM | 6.1 | Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1, tract-nnef uses unchecked usize multiplication in nnef/src/tensors.rs read_tensor … | Sep 14, 2026 |
| CVE-2026-54632 | HIGH | 7.5 | SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPacketReceived and the STUNAttribute.ParseMessageAttributes, STUNXORAddressAttribute, and STUNAddressAttribute parsing path index … | Sep 14, 2026 |
| CVE-2026-54629 | HIGH | 7.5 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader … | Sep 14, 2026 |
| CVE-2026-54628 | HIGH | 8.6 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtual table modules such as json_reader … | Sep 14, 2026 |
| CVE-2026-54559 | UNKNOWN | — | PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie language-model loaders in src/lm/ngram_model_trie.c do not adequately validate boundary conditions in ARPA, DMP, and … | Sep 14, 2026 |
| CVE-2026-54447 | HIGH | 8.4 | garminconnect is a Python 3 API wrapper for Garmin Connect that retrieves statistics and manages activities. Prior to 0.3.5, garminconnect/client.py Client.dump creates the OAuth token … | Sep 14, 2026 |
| CVE-2026-54334 | CRITICAL | 9.8 | UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, ReadCLen() in uefi_firmware/compression/Tiano/Decompress.c reads Number … | Sep 14, 2026 |
| CVE-2026-54333 | CRITICAL | 9.8 | UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, MakeTable() in uefi_firmware/compression/Tiano/Decompress.c does not … | Sep 14, 2026 |
| CVE-2026-54247 | MEDIUM | 4.3 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes/admission/admission.go passes the body of requests to the Kubernetes … | Sep 14, 2026 |
| CVE-2026-54246 | MEDIUM | 5.7 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves cluster-wide control-plane data without application-layer authentication through … | Sep 14, 2026 |
| CVE-2026-53717 | MEDIUM | 6.5 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows … | Sep 14, 2026 |
| CVE-2026-50006 | CRITICAL | 9.1 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to … | Sep 14, 2026 |
| CVE-2026-47253 | HIGH | 7.3 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar function in namespace/other_functions.go passes the caller-controlled plugin … | Sep 14, 2026 |
| CVE-2026-19816 | HIGH | 7.1 | A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove … | Sep 14, 2026 |
| CVE-2026-19624 | HIGH | 7.8 | A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto … | Sep 14, 2026 |
| CVE-2026-18251 | MEDIUM | 4.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation of the WebSocket origin. | Sep 14, 2026 |
| CVE-2026-18119 | UNKNOWN | — | Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page CSS via a DOM sink, … | Sep 14, 2026 |
| CVE-2026-18065 | MEDIUM | 5.3 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive information through session IP binding bypass in … | Sep 14, 2026 |
| CVE-2026-17628 | MEDIUM | 5.4 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account due to improper authentication. | Sep 14, 2026 |
| CVE-2026-17467 | HIGH | 8.2 | IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due to the use of weak or … | Sep 14, 2026 |
| CVE-2026-17463 | MEDIUM | 6.5 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to … | Sep 14, 2026 |
| CVE-2026-17416 | HIGH | 7.8 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization. | Sep 14, 2026 |
| CVE-2026-17156 | HIGH | 7.8 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization. | Sep 14, 2026 |
| CVE-2026-17133 | HIGH | 7.8 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to improper neutralization of … | Sep 14, 2026 |
| CVE-2026-17047 | MEDIUM | 5.4 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to improper request validation. | Sep 14, 2026 |