Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
57401
Total
4583
Critical
17032
High
16919
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-76443 | CRITICAL | 9.8 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering … | Sep 14, 2026 |
| CVE-2026-76442 | HIGH | 7.5 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering … | Sep 14, 2026 |
| CVE-2026-76441 | CRITICAL | 9.8 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering … | Sep 14, 2026 |
| CVE-2026-76440 | CRITICAL | 9.8 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering … | Sep 14, 2026 |
| CVE-2026-61701 | HIGH | 8.8 | Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 until 2.25.1, MagicLink stores serialized action objects in the … | Sep 14, 2026 |
| CVE-2026-59960 | HIGH | 7.5 | Argos JavaScript provides official Argos SDKs for JavaScript. Prior to Argos core package version 6.2.1, attacker-controlled CI branch or ref values from GITHUB_HEAD_REF or ARGOS_BRANCH … | Sep 14, 2026 |
| CVE-2026-57579 | HIGH | 7.5 | Alchemy is an open source content management system engine written in Ruby on Rails. Prior to 7.4.15, 8.0.15, 8.1.14, and 8.2.6, the unauthenticated GET /api/pages/nested … | Sep 14, 2026 |
| CVE-2026-57497 | MEDIUM | 5.3 | webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule() in session.go skips an unknown WebTransport capsule on the HTTP/3 request stream by … | Sep 14, 2026 |
| CVE-2026-55837 | MEDIUM | 6.8 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_mcp/oauth/fastapi_app.py exposes GET /dbt_platform_context without authentication … | Sep 14, 2026 |
| CVE-2026-55451 | UNKNOWN | — | gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() in lib/js2i18next.js splits nested translation keys using options.keyseparator, whose default value consists of … | Sep 14, 2026 |
| CVE-2026-55416 | HIGH | 8.8 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticated user with reports_config permission can place attacker-controlled … | Sep 14, 2026 |
| CVE-2026-55102 | UNKNOWN | — | hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src/Vault.js passes failed requests through parseAxiosError(), … | Sep 14, 2026 |
| CVE-2026-55073 | MEDIUM | 6.2 | WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restrictive url_fetcher and pass attacker-influenced values to HTML.write_pdf() can … | Sep 14, 2026 |
| CVE-2026-55072 | HIGH | 8.5 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objects permission can submit a malicious ClassDefinition … | Sep 14, 2026 |
| CVE-2026-54452 | UNKNOWN | — | safeurl is a server-side request forgery protection library. Prior to 0.2.4, the privateNetworks list in ip.go omits the IPv6 ranges 64:ff9b:1::/48, 5f00::/16, 3fff::/20, and 100:0:0:1::/64. … | Sep 14, 2026 |
| CVE-2026-54156 | HIGH | 7.5 | node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNonce cache used by nonceAlreadyBeenUsed in packages/node-opcua-secure-channel/source/server/server_secure_channel_layer.ts records nonces from … | Sep 14, 2026 |
| CVE-2026-54155 | HIGH | 7.7 | node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentication handler in packages/node-opcua-server/source/opcua_server.ts decrypts an RSA-OAEP password blob but … | Sep 14, 2026 |
| CVE-2026-53496 | MEDIUM | 5.3 | ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URL loaders can pass attacker-supplied HEIC or AVIF data … | Sep 14, 2026 |
| CVE-2026-20353 | CRITICAL | 9.8 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering … | Sep 14, 2026 |
| CVE-2026-15923 | MEDIUM | 4.6 | The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a byte-I/O loop that uses size = MIN(remaining, func->cis.max_blk_size) as the per-iteration step. The … | Sep 14, 2026 |
| CVE-2026-90996 | MEDIUM | 4.0 | A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services … | Sep 14, 2026 |
| CVE-2026-90995 | MEDIUM | 5.5 | A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket … | Sep 14, 2026 |
| CVE-2026-90994 | MEDIUM | 4.0 | A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data(). A local client with access to the … | Sep 14, 2026 |
| CVE-2026-90947 | HIGH | 7.8 | A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not properly validate the number of … | Sep 14, 2026 |
| CVE-2026-90943 | HIGH | 8.7 | parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering that allows authenticated panel users to inject malicious scripts. Attackers can … | Sep 14, 2026 |