Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54256
Total
4300
Critical
16127
High
15827
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-103113 | MEDIUM | 4.7 | A vulnerability was determined in OS4ED openSIS-Classic up to 9.3. The affected element is the function save action of the file modules/students/Student.php of the component … | Sep 30, 2026 |
| CVE-2026-94053 | CRITICAL | 9.1 | Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a … | Sep 30, 2026 |
| CVE-2026-94052 | CRITICAL | 9.1 | A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA … | Sep 30, 2026 |
| CVE-2026-94029 | MEDIUM | 6.5 | Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension. Apache MINA SSHD … | Sep 30, 2026 |
| CVE-2026-94002 | HIGH | 7.5 | Possible memory exhaustion in SFTP clients (DefaultSftpClient) in component sshd-sftp in Apache MINA SSHD versions 0.9.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD … | Sep 30, 2026 |
| CVE-2026-93996 | MEDIUM | 6.5 | Uncontrolled resource consumption in component ssd-scp in Apache MINA SSHD versions up to 2.19.0 or 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library … | Sep 30, 2026 |
| CVE-2026-93995 | MEDIUM | 6.5 | Improper input validation in sshd-git in Apache MINA SSHD, versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for … | Sep 30, 2026 |
| CVE-2026-93994 | HIGH | 8.1 | Apache MINA SSHD is a Java library for client-side and server-side SSH. SSH servers can be configured to require multi-authentication schemes, for instance two different … | Sep 30, 2026 |
| CVE-2026-79625 | HIGH | 8.1 | Affected products do not properly synchronize access to their monitoring functionality. When multiple clients send concurrent requests, this may lead to incorrect reads or writes, … | Sep 30, 2026 |
| CVE-2026-77185 | CRITICAL | 9.1 | Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an … | Sep 30, 2026 |
| CVE-2026-10764 | HIGH | 8.7 | Information disclosure in BVMS 4.5 up to 12.3 including allows man-in-the-middle attackers to gain unauthorized access to sensitive data. | Sep 30, 2026 |
| CVE-2026-103237 | UNKNOWN | — | MISP contains an improper input validation vulnerability in its ORM save path. When a user submits data through various endpoints (attribute add/edit, event edit, free-text … | Sep 30, 2026 |
| CVE-2026-103235 | UNKNOWN | — | MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the … | Sep 30, 2026 |
| CVE-2026-97347 | HIGH | 7.2 | The Post Views Stats Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 1.1.7 … | Sep 30, 2026 |
| CVE-2026-93908 | MEDIUM | 6.4 | The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_price_text' parameter in all … | Sep 30, 2026 |
| CVE-2026-92712 | MEDIUM | 6.4 | The ReactPress – Create React App for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permalink' parameter in all versions up … | Sep 30, 2026 |
| CVE-2026-75098 | HIGH | 7.5 | The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.3 via the 'svg' parameter parameter. … | Sep 30, 2026 |
| CVE-2026-102588 | MEDIUM | 6.5 | A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with … | Sep 30, 2026 |
| CVE-2026-102587 | LOW | 2.7 | A flaw was found in Moodle. User list filters do not properly enforce visibility restrictions on user profile fields. An authorized user with manager privileges … | Sep 30, 2026 |
| CVE-2026-102586 | MEDIUM | 4.3 | A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting … | Sep 30, 2026 |
| CVE-2026-102585 | MEDIUM | 4.3 | A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether … | Sep 30, 2026 |
| CVE-2026-102584 | MEDIUM | 4.3 | A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding … | Sep 30, 2026 |
| CVE-2026-102583 | LOW | 2.7 | A flaw was found in Moodle. An incorrect capability check in the artificial intelligence (AI) editor placement's image generation web service allows an authenticated user … | Sep 30, 2026 |
| CVE-2026-102582 | LOW | 2.2 | A flaw was found in Moodle. The manual enrolment management page did not properly check whether the manual enrolment plugin was disabled, allowing users with … | Sep 30, 2026 |
| CVE-2026-102581 | MEDIUM | 4.6 | A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker … | Sep 30, 2026 |