Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54274
Total
4303
Critical
16132
High
15830
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-75804 | MEDIUM | 5.3 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit … | Sep 29, 2026 |
| CVE-2026-72897 | HIGH | 7.5 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond … | Sep 29, 2026 |
| CVE-2026-54875 | LOW | 3.7 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An … | Sep 29, 2026 |
| CVE-2026-54873 | UNKNOWN | — | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability … | Sep 29, 2026 |
| CVE-2026-54872 | LOW | 3.7 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information … | Sep 29, 2026 |
| CVE-2026-42772 | UNKNOWN | — | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional … | Sep 29, 2026 |
| CVE-2026-35191 | UNKNOWN | — | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated … | Sep 29, 2026 |
| CVE-2026-35189 | UNKNOWN | — | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate … | Sep 29, 2026 |
| CVE-2026-19743 | HIGH | 7.8 | Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a … | Sep 29, 2026 |
| CVE-2026-102630 | MEDIUM | 4.7 | UnoPim versions before 2.0.1 and 2.1.1 trust all connecting clients as proxies and honor the X-Forwarded-Host header without validation, allowing unauthenticated attackers to inject arbitrary … | Sep 29, 2026 |
| CVE-2026-102601 | LOW | 3.5 | Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match … | Sep 29, 2026 |
| CVE-2026-102600 | HIGH | 7.5 | Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @socket.io/cluster-engine uses inherited object properties when looking up attacker-controlled session IDs in clustered … | Sep 29, 2026 |
| CVE-2026-102598 | UNKNOWN | — | Werkzeug is a comprehensive WSGI web application library. Prior to 3.1.9, the safe_join function used by send_from_directory can allow a NUL: special-device path because safe_join … | Sep 29, 2026 |
| CVE-2026-100308 | HIGH | 7.8 | Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary operating system commands with … | Sep 29, 2026 |
| CVE-2026-100289 | MEDIUM | 5.0 | Missing authorization in the gateway network scan token API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to generate a network scan … | Sep 29, 2026 |
| CVE-2026-100288 | UNKNOWN | — | Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain … | Sep 29, 2026 |
| CVE-2026-100287 | MEDIUM | 5.4 | Missing authorization in the attachment history API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to permanently delete or restore vault attachments … | Sep 29, 2026 |
| CVE-2026-100286 | MEDIUM | 6.5 | Missing authorization in the data source settings API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated non-administrative user to disclose integration secrets via a … | Sep 29, 2026 |
| CVE-2023-54400 | CRITICAL | 9.8 | Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter … | Sep 29, 2026 |
| CVE-2026-86035 | HIGH | 8.5 | Weblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 through 2026.7.1 contains an argument-injection vulnerability in its Mercurial backend. Repository … | Sep 29, 2026 |
| CVE-2026-68911 | UNKNOWN | — | Nicotine+ is a graphical client for the Soulseek peer-to-peer network. Prior to version 3.3.11, a modified remote client can send zlib-compressed peer messages containing a … | Sep 29, 2026 |
| CVE-2026-65102 | HIGH | 7.8 | NVIDIA DeepStream contains a vulnerability where an attacker could cause an integer overflow by supplying crafted tensor dimensions in a YAML configuration file. A successful … | Sep 29, 2026 |
| CVE-2026-63209 | HIGH | 7.5 | compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by … | Sep 29, 2026 |
| CVE-2026-49243 | UNKNOWN | — | Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.650, Webmin users who click on a malicious link to their server … | Sep 29, 2026 |
| CVE-2026-22101 | UNKNOWN | — | The access to the service menu is obfuscated, but possible with only physical access. This menu exposes sensitive information such as serial numbers, MAC addresses, … | Sep 29, 2026 |