Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54274
Total
4303
Critical
16132
High
15830
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-100245 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Stored XSS. This issue … | Sep 29, 2026 |
| CVE-2026-100244 | UNKNOWN | — | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows Excavation. This issue affects Mediawiki - CentralAuth Extension: … | Sep 29, 2026 |
| CVE-2026-100243 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - WikiSEO Extension allows Stored XSS. This issue … | Sep 29, 2026 |
| CVE-2026-100242 | UNKNOWN | — | Dependency on Vulnerable Third-Party Component and Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - DataTransfer Extension allows Excessive Allocation. This issue affects Mediawiki - … | Sep 29, 2026 |
| CVE-2026-100241 | UNKNOWN | — | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - EventBus Extension allows Excavation. This issue affects Mediawiki - EventBus Extension: … | Sep 29, 2026 |
| CVE-2026-100240 | UNKNOWN | — | Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - TemplateSandbox Extension: … | Sep 29, 2026 |
| CVE-2026-100238 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Flow Extension allows Stored XSS. This issue … | Sep 29, 2026 |
| CVE-2022-51019 | HIGH | 8.8 | Akaunting before 2.1.31 contains an OS command injection vulnerability in the module installation and update flow where the alias parameter is passed unvalidated to shell … | Sep 29, 2026 |
| CVE-2026-97711 | UNKNOWN | — | Serialize JavaScript serializes JavaScript values to a superset of JSON that includes regular expressions and functions. From 7.1.1 until 7.1.2, function values serialized by serialize-javascript … | Sep 29, 2026 |
| CVE-2026-97689 | UNKNOWN | — | urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk … | Sep 29, 2026 |
| CVE-2026-97688 | UNKNOWN | — | urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains … | Sep 29, 2026 |
| CVE-2026-97687 | UNKNOWN | — | urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail … | Sep 29, 2026 |
| CVE-2026-93332 | UNKNOWN | — | Improper access control in the partial connection API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to read, create, modify, and delete … | Sep 29, 2026 |
| CVE-2026-93330 | MEDIUM | 4.3 | Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions Gateway … | Sep 29, 2026 |
| CVE-2026-92371 | HIGH | 7.0 | TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting … | Sep 29, 2026 |
| CVE-2026-92370 | HIGH | 8.8 | An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to … | Sep 29, 2026 |
| CVE-2026-92369 | HIGH | 7.3 | TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker … | Sep 29, 2026 |
| CVE-2026-92368 | HIGH | 7.8 | TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording … | Sep 29, 2026 |
| CVE-2026-84784 | HIGH | 7.5 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs … | Sep 29, 2026 |
| CVE-2026-84783 | HIGH | 7.5 | Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached extension data to be freed while another … | Sep 29, 2026 |
| CVE-2026-84782 | HIGH | 8.2 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read … | Sep 29, 2026 |
| CVE-2026-77696 | LOW | 3.7 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times … | Sep 29, 2026 |
| CVE-2026-77177 | CRITICAL | 9.8 | Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with … | Sep 29, 2026 |
| CVE-2026-75806 | MEDIUM | 5.3 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter … | Sep 29, 2026 |
| CVE-2026-75805 | MEDIUM | 5.3 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when … | Sep 29, 2026 |