Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54274
Total
4303
Critical
16132
High
15830
Medium
CVE ID Severity Score Description Published
CVE-2026-100245 UNKNOWN — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Stored XSS. This issue … Sep 29, 2026
CVE-2026-100244 UNKNOWN — Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows Excavation. This issue affects Mediawiki - CentralAuth Extension: … Sep 29, 2026
CVE-2026-100243 UNKNOWN — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - WikiSEO Extension allows Stored XSS. This issue … Sep 29, 2026
CVE-2026-100242 UNKNOWN — Dependency on Vulnerable Third-Party Component and Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - DataTransfer Extension allows Excessive Allocation. This issue affects Mediawiki - … Sep 29, 2026
CVE-2026-100241 UNKNOWN — Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - EventBus Extension allows Excavation. This issue affects Mediawiki - EventBus Extension: … Sep 29, 2026
CVE-2026-100240 UNKNOWN — Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - TemplateSandbox Extension: … Sep 29, 2026
CVE-2026-100238 UNKNOWN — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Flow Extension allows Stored XSS. This issue … Sep 29, 2026
CVE-2022-51019 HIGH 8.8 Akaunting before 2.1.31 contains an OS command injection vulnerability in the module installation and update flow where the alias parameter is passed unvalidated to shell … Sep 29, 2026
CVE-2026-97711 UNKNOWN — Serialize JavaScript serializes JavaScript values to a superset of JSON that includes regular expressions and functions. From 7.1.1 until 7.1.2, function values serialized by serialize-javascript … Sep 29, 2026
CVE-2026-97689 UNKNOWN — urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk … Sep 29, 2026
CVE-2026-97688 UNKNOWN — urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains … Sep 29, 2026
CVE-2026-97687 UNKNOWN — urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE configuration paths fail … Sep 29, 2026
CVE-2026-93332 UNKNOWN — Improper access control in the partial connection API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to read, create, modify, and delete … Sep 29, 2026
CVE-2026-93330 MEDIUM 4.3 Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions Gateway … Sep 29, 2026
CVE-2026-92371 HIGH 7.0 TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting … Sep 29, 2026
CVE-2026-92370 HIGH 8.8 An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to … Sep 29, 2026
CVE-2026-92369 HIGH 7.3 TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker … Sep 29, 2026
CVE-2026-92368 HIGH 7.8 TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording … Sep 29, 2026
CVE-2026-84784 HIGH 7.5 Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs … Sep 29, 2026
CVE-2026-84783 HIGH 7.5 Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached extension data to be freed while another … Sep 29, 2026
CVE-2026-84782 HIGH 8.2 Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read … Sep 29, 2026
CVE-2026-77696 LOW 3.7 Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times … Sep 29, 2026
CVE-2026-77177 CRITICAL 9.8 Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with … Sep 29, 2026
CVE-2026-75806 MEDIUM 5.3 Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter … Sep 29, 2026
CVE-2026-75805 MEDIUM 5.3 Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when … Sep 29, 2026