Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57401
Total
4583
Critical
17032
High
16919
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-54176 | MEDIUM | 6.5 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 … | Sep 14, 2026 |
| CVE-2026-54175 | HIGH | 7.6 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to … | Sep 14, 2026 |
| CVE-2026-54150 | UNKNOWN | — | next-video is a library for adding video to Next.js applications. Prior to 2.8.1, the GET endpoint exported by next-video/request-handler and commonly mounted at /api/video accepts … | Sep 14, 2026 |
| CVE-2026-54087 | HIGH | 7.6 | EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageField can accept browser-executable uploads while templates/crud/field/file.html.twig links … | Sep 14, 2026 |
| CVE-2026-53752 | HIGH | 7.5 | docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files. Prior to 11.5.14, PropertyResolver and … | Sep 14, 2026 |
| CVE-2026-53659 | HIGH | 7.5 | http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0, ServerFilters.GZip, RequestFilters.GunZip, and the underlying Gzip request-body decompression functions impose … | Sep 14, 2026 |
| CVE-2026-53495 | UNKNOWN | — | containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the … | Sep 14, 2026 |
| CVE-2026-50276 | HIGH | 7.5 | dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults … | Sep 14, 2026 |
| CVE-2026-50270 | HIGH | 7.5 | dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which … | Sep 14, 2026 |
| CVE-2026-50157 | MEDIUM | 6.5 | Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security … | Sep 14, 2026 |
| CVE-2026-49400 | LOW | 3.3 | October System provides the system module for October Content Management System. Prior to versions 3.7.17 and 4.2.21, the backend `SessionMaker` trait stored widget session state … | Sep 14, 2026 |
| CVE-2026-49250 | UNKNOWN | — | Conform, a type-safe form validation library, allows the parsing of nested objects in the form of object.property. From 1.8.0 until 1.19.4, the parseSubmission future API … | Sep 14, 2026 |
| CVE-2026-47256 | MEDIUM | 5.3 | OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and … | Sep 14, 2026 |
| CVE-2026-46696 | LOW | 3.3 | October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 have a vulnerability in the Twig sandbox security … | Sep 14, 2026 |
| CVE-2026-44162 | LOW | 2.7 | fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd. From 0.7.0 to 1.8.4, the in_s3 input plugin reads the entire decompressed payload of … | Sep 14, 2026 |
| CVE-2026-34151 | UNKNOWN | — | XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended … | Sep 14, 2026 |
| CVE-2026-19542 | MEDIUM | 5.6 | Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an … | Sep 14, 2026 |
| CVE-2026-19499 | HIGH | 7.7 | Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a … | Sep 14, 2026 |
| CVE-2026-90804 | MEDIUM | 4.8 | A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame … | Sep 14, 2026 |
| CVE-2026-90803 | MEDIUM | 5.3 | A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component … | Sep 14, 2026 |
| CVE-2026-90802 | MEDIUM | 4.4 | A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes … | Sep 14, 2026 |
| CVE-2026-90801 | MEDIUM | 5.3 | A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation … | Sep 14, 2026 |
| CVE-2026-90796 | MEDIUM | 6.3 | A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/company/index.php. The manipulation of the argument ID … | Sep 14, 2026 |
| CVE-2026-84445 | UNKNOWN | — | gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither … | Sep 14, 2026 |
| CVE-2026-76461 | CRITICAL | 9.8 | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands … | Sep 14, 2026 |