Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-100253 | HIGH | 8.8 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL | Sep 30, 2026 |
| CVE-2026-97259 | UNKNOWN | — | Authorization Bypass Through User-Controlled Key vulnerability in WP Hosting AS Pay with Vipps for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue … | Sep 30, 2026 |
| CVE-2026-94545 | UNKNOWN | — | Satori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27 and prior to version 0.33.5, Satori does not properly escape … | Sep 30, 2026 |
| CVE-2026-76570 | UNKNOWN | — | Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla … | Sep 30, 2026 |
| CVE-2026-62097 | HIGH | 7.6 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPTasty Business Directory business-directory-plugin allows Blind SQL Injection.This issue affects Business … | Sep 30, 2026 |
| CVE-2026-62084 | MEDIUM | 6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS. This issue affects User Submitted … | Sep 30, 2026 |
| CVE-2026-47097 | HIGH | 7.5 | AJA HELO Plus firmware before 2.1.7 contains an information disclosure vulnerability that allows unauthenticated attackers to decrypt sensitive diagnostics bundles by exploiting a static AES … | Sep 30, 2026 |
| CVE-2026-18783 | HIGH | 8.8 | Missing authentication for critical function vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Authentication Bypass. This issue affects Trex MES: through 2026-09-29. | Sep 30, 2026 |
| CVE-2026-18782 | CRITICAL | 9.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line … | Sep 30, 2026 |
| CVE-2026-103398 | HIGH | 8.1 | OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured … | Sep 30, 2026 |
| CVE-2026-103397 | MEDIUM | 5.6 | OpenSave before 2.4.0-beta.1 fails to validate sender identity in WAN relay requests, allowing unpaired room members to impersonate paired devices by spoofing the RelayMessage From … | Sep 30, 2026 |
| CVE-2026-103396 | MEDIUM | 4.3 | bbs-go through 4.4.6 contains a permission bypass vulnerability in the AdminMiddleware authorization logic where the read-only dashboard.user.view permission rule matches the /api/admin/user/synccount endpoint before the … | Sep 30, 2026 |
| CVE-2026-103395 | CRITICAL | 9.8 | LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attackers can reach the … | Sep 30, 2026 |
| CVE-2026-103389 | UNKNOWN | — | MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any … | Sep 30, 2026 |
| CVE-2026-103388 | UNKNOWN | — | MISP renders the source field of a Galaxy Cluster as a clickable hyperlink whenever the stored value passes PHP's FILTER_VALIDATE_URL validation. Because FILTER_VALIDATE_URL accepts the … | Sep 30, 2026 |
| CVE-2026-103270 | HIGH | 7.5 | LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, … | Sep 30, 2026 |
| CVE-2026-103243 | MEDIUM | 5.8 | LightLLM through 1.2.0 fails to validate image_url and audio_url parameters in multimodal endpoints, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply arbitrary … | Sep 30, 2026 |
| CVE-2026-103227 | MEDIUM | 6.3 | A weakness has been identified in GPAC up to 26.07.0. Affected by this issue is the function gf_dash_resolve_url of the file src/media_tools/dash_client.c of the component … | Sep 30, 2026 |
| CVE-2026-103226 | MEDIUM | 6.3 | A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation … | Sep 30, 2026 |
| CVE-2026-103222 | MEDIUM | 5.6 | A vulnerability was determined in Blosc C-Blosc2 up to 3.3.2. This impacts the function blosclz_decompress of the file blosc/blosclz.c of the component blosclz Decompression. Executing … | Sep 30, 2026 |
| CVE-2026-102984 | UNKNOWN | — | Astro is a web framework for content-driven websites. Prior to 11.1.3, the @astrojs/node adapter builds a request URL from the Host header, and a malformed … | Sep 30, 2026 |
| CVE-2026-102983 | UNKNOWN | — | Astro is a web framework for content-driven websites. From 5.2.0 until 8.2.4, the @astrojs/netlify adapter generates regular expressions for Netlify Image CDN remote-image allowlists without … | Sep 30, 2026 |
| CVE-2026-102717 | HIGH | 7.5 | MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash | Sep 30, 2026 |
| CVE-2026-101295 | HIGH | 7.3 | Path traversal / arbitrary file write in oc-mirror's operator catalog image extraction. When mirroring operator catalogs using either the legacy v1 path (--v1) or the … | Sep 30, 2026 |
| CVE-2026-93903 | UNKNOWN | — | LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case." | Sep 30, 2026 |