Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54256
Total
4300
Critical
16127
High
15827
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-102580 | LOW | 2.2 | A flaw was found in Moodle. An authenticated attacker can supply an improperly validated audience class name to the Report Builder component, allowing arbitrary class … | Sep 30, 2026 |
| CVE-2026-102579 | MEDIUM | 4.3 | A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other … | Sep 30, 2026 |
| CVE-2026-102578 | MEDIUM | 5.5 | A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, … | Sep 30, 2026 |
| CVE-2026-102577 | MEDIUM | 4.3 | A flaw was found in Moodle. Incorrect handling of IPv4-mapped IPv6 addresses within the URL downloader's host-blocking logic allows an authenticated remote user to bypass … | Sep 30, 2026 |
| CVE-2026-102511 | UNKNOWN | — | Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to … | Sep 30, 2026 |
| CVE-2026-102510 | UNKNOWN | — | Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value in the Go implementation of Apache PLC4X (PLC4Go) allow … | Sep 30, 2026 |
| CVE-2026-102509 | UNKNOWN | — | Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious … | Sep 30, 2026 |
| CVE-2026-102459 | MEDIUM | 6.1 | EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability. Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks. | Sep 30, 2026 |
| CVE-2026-102458 | CRITICAL | 9.8 | EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API. | Sep 30, 2026 |
| CVE-2026-102457 | MEDIUM | 6.5 | EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability. Authenticated remote attackers can exploit this vulnerability to download arbitrary system files. | Sep 30, 2026 |
| CVE-2026-102456 | MEDIUM | 6.5 | EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents. | Sep 30, 2026 |
| CVE-2026-102455 | CRITICAL | 9.8 | EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized … | Sep 30, 2026 |
| CVE-2026-102454 | HIGH | 7.2 | EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code … | Sep 30, 2026 |
| CVE-2025-14564 | MEDIUM | 6.4 | The Viable URL Media Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, … | Sep 30, 2026 |
| CVE-2026-97150 | HIGH | 7.2 | When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files … | Sep 30, 2026 |
| CVE-2026-93464 | MEDIUM | 5.4 | Stored Cross-Site Scripting via custom content descriptions vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be executed in the … | Sep 30, 2026 |
| CVE-2026-93463 | MEDIUM | 5.4 | Cross-Site Scripting via Script Validation Bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser … | Sep 30, 2026 |
| CVE-2026-93462 | MEDIUM | 5.3 | Missing authentication for critical function vulnerability exists in baserCMS . If a remote unauthenticated attacker there is a possibility that sensitive information could be obtained. | Sep 30, 2026 |
| CVE-2026-93460 | MEDIUM | 5.4 | Stored Cross-site scripting via appended strings in email form fields vulnerability exists in baserCMS . If this vulnerability is exploited, an arbitrary script may be … | Sep 30, 2026 |
| CVE-2026-92873 | HIGH | 7.3 | Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node. | Sep 30, 2026 |
| CVE-2026-92872 | MEDIUM | 4.3 | Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information. | Sep 30, 2026 |
| CVE-2026-92871 | HIGH | 7.5 | A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process. | Sep 30, 2026 |
| CVE-2026-92870 | HIGH | 7.5 | A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination. | Sep 30, 2026 |
| CVE-2026-92869 | MEDIUM | 6.5 | An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination. | Sep 30, 2026 |
| CVE-2026-92868 | MEDIUM | 6.5 | An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication. | Sep 30, 2026 |