Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57401
Total
4583
Critical
17032
High
16919
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-90806 | MEDIUM | 6.3 | A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk … | Sep 14, 2026 |
| CVE-2026-90805 | HIGH | 7.3 | A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. This affects an unknown part of the file doctorlogin.php. Executing a manipulation of the … | Sep 14, 2026 |
| CVE-2026-86836 | UNKNOWN | — | In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the … | Sep 14, 2026 |
| CVE-2026-85921 | HIGH | 8.2 | Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | Sep 14, 2026 |
| CVE-2026-85892 | HIGH | 7.8 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally. | Sep 14, 2026 |
| CVE-2026-73494 | HIGH | 7.4 | blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.0-M1 until 1.0.0-M42, five HTTP/1.1 … | Sep 14, 2026 |
| CVE-2026-70658 | HIGH | 7.4 | Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11.6.2, Pay::Webhooks::PaddleBillingController#valid_signature? in app/controllers/pay/webhooks/paddle_billing_controller.rb compares the computed 64-character SHA-256 HMAC with … | Sep 14, 2026 |
| CVE-2026-57583 | LOW | 3.3 | OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Prior to @openzeppelin/wizard 0.10.11, @openzeppelin/wizard-cairo 3.0.1, @openzeppelin/wizard-stellar … | Sep 14, 2026 |
| CVE-2026-57581 | MEDIUM | 5.3 | DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applications with configured file upload storage allow unauthenticated users … | Sep 14, 2026 |
| CVE-2026-57578 | UNKNOWN | — | DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, AuthorizeActionFilter performs no authorization because its explicit ICommandActionFilter.OnCommandExecutingAsync, IViewModelActionFilter.OnViewModelCreatedAsync, … | Sep 14, 2026 |
| CVE-2026-57577 | UNKNOWN | — | DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, a route containing multiple unconstrained parameters in one path … | Sep 14, 2026 |
| CVE-2026-57570 | MEDIUM | 6.5 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 … | Sep 14, 2026 |
| CVE-2026-55866 | LOW | 3.7 | SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34.0 until 1.54.0, SpiceDB can return PERMISSIONSHIP_HAS_PERMISSION instead of PERMISSIONSHIP_CONDITIONAL_PERMISSION … | Sep 14, 2026 |
| CVE-2026-55847 | MEDIUM | 6.1 | Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js helper at allure-generator/src/main/javascript/helpers/ansi.js passes attacker-influenced … | Sep 14, 2026 |
| CVE-2026-55846 | MEDIUM | 6.2 | Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP server started by allure serve … | Sep 14, 2026 |
| CVE-2026-55832 | MEDIUM | 6.1 | Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2, the tract-onnx crate passes the attacker-controlled external_data location … | Sep 14, 2026 |
| CVE-2026-55253 | HIGH | 7.7 | LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0, MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search() incorporate filter dictionaries into … | Sep 14, 2026 |
| CVE-2026-55091 | HIGH | 7.5 | flat-to-nested converts a hierarchy from a flat representation to a nested representation. Prior to 1.1.2, FlatToNested.prototype.convert in index.js uses attacker-influenced id and parent record fields … | Sep 14, 2026 |
| CVE-2026-54723 | MEDIUM | 6.5 | devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a server configured with the primary … | Sep 14, 2026 |
| CVE-2026-54567 | HIGH | 7.5 | Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the case-preserving … | Sep 14, 2026 |
| CVE-2026-54182 | HIGH | 8.1 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to … | Sep 14, 2026 |
| CVE-2026-54181 | MEDIUM | 5.4 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 … | Sep 14, 2026 |
| CVE-2026-54180 | HIGH | 7.6 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 … | Sep 14, 2026 |
| CVE-2026-54178 | HIGH | 8.1 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to … | Sep 14, 2026 |
| CVE-2026-54177 | MEDIUM | 6.6 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 … | Sep 14, 2026 |