Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54256
Total
4300
Critical
16127
High
15827
Medium
CVE ID Severity Score Description Published
CVE-2026-103113 MEDIUM 4.7 A vulnerability was determined in OS4ED openSIS-Classic up to 9.3. The affected element is the function save action of the file modules/students/Student.php of the component … Sep 30, 2026
CVE-2026-94053 CRITICAL 9.1 Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a … Sep 30, 2026
CVE-2026-94052 CRITICAL 9.1 A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA … Sep 30, 2026
CVE-2026-94029 MEDIUM 6.5 Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension. Apache MINA SSHD … Sep 30, 2026
CVE-2026-94002 HIGH 7.5 Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD … Sep 30, 2026
CVE-2026-93996 MEDIUM 6.5 Uncontrolled resource consumption in component ssd-scp in Apache MINA SSHD versions up to 2.19.0 or 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library … Sep 30, 2026
CVE-2026-93995 MEDIUM 6.5 Improper input validation in sshd-git in Apache MINA SSHD, versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for … Sep 30, 2026
CVE-2026-93994 HIGH 8.1 Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different … Sep 30, 2026
CVE-2026-79625 HIGH 8.1 Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, … Sep 30, 2026
CVE-2026-77185 CRITICAL 9.1 Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an … Sep 30, 2026
CVE-2026-10764 HIGH 8.7 Information disclosure in BVMS 4.5 up to 12.3 including allows man-in-the-middle attackers to gain unauthorized access to sensitive data. Sep 30, 2026
CVE-2026-103237 UNKNOWN — MISP contains an improper input validation vulnerability in its ORM save path. When a user submits data through various endpoints (attribute add/edit, event edit, free-text … Sep 30, 2026
CVE-2026-103235 UNKNOWN — MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the … Sep 30, 2026
CVE-2026-97347 HIGH 7.2 The Post Views Stats Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 1.1.7 … Sep 30, 2026
CVE-2026-93908 MEDIUM 6.4 The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_price_text' parameter in all … Sep 30, 2026
CVE-2026-92712 MEDIUM 6.4 The ReactPress – Create React App for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permalink' parameter in all versions up … Sep 30, 2026
CVE-2026-75098 HIGH 7.5 The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.3 via the 'svg' parameter parameter. … Sep 30, 2026
CVE-2026-102588 MEDIUM 6.5 A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with … Sep 30, 2026
CVE-2026-102587 LOW 2.7 A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges … Sep 30, 2026
CVE-2026-102586 MEDIUM 4.3 A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting … Sep 30, 2026
CVE-2026-102585 MEDIUM 4.3 A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether … Sep 30, 2026
CVE-2026-102584 MEDIUM 4.3 A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding … Sep 30, 2026
CVE-2026-102583 LOW 2.7 A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user … Sep 30, 2026
CVE-2026-102582 LOW 2.2 A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with … Sep 30, 2026
CVE-2026-102581 MEDIUM 4.6 A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker … Sep 30, 2026