Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54274
Total
4303
Critical
16132
High
15830
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-7192 | UNKNOWN | — | A stack-based buffer overflow vulnerability in the Dbit T-CPE301K 4G WiFi minirouter allows an authenticated attacker to cause a denial of service (DoS) and a … | Sep 29, 2026 |
| CVE-2026-76875 | MEDIUM | 5.3 | PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a … | Sep 29, 2026 |
| CVE-2026-76114 | MEDIUM | 5.9 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access … | Sep 29, 2026 |
| CVE-2026-73599 | MEDIUM | 5.4 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with … | Sep 29, 2026 |
| CVE-2026-73598 | HIGH | 7.8 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with … | Sep 29, 2026 |
| CVE-2026-102437 | HIGH | 7.8 | OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) … | Sep 29, 2026 |
| CVE-2026-101271 | UNKNOWN | — | OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled. | Sep 29, 2026 |
| CVE-2026-101270 | UNKNOWN | — | Malicious HTML content could be injected into the help texts of various fields with organizer permissions. | Sep 29, 2026 |
| CVE-2026-101269 | UNKNOWN | — | The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is used for all token-based API … | Sep 29, 2026 |
| CVE-2026-101268 | UNKNOWN | — | If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account. If … | Sep 29, 2026 |
| CVE-2026-101267 | UNKNOWN | — | A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This … | Sep 29, 2026 |
| CVE-2026-100832 | HIGH | 8.8 | Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Firefox ESR 115.42, and Firefox ESR 140.17. | Sep 29, 2026 |
| CVE-2026-100831 | HIGH | 8.8 | Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | Sep 29, 2026 |
| CVE-2026-100830 | UNKNOWN | — | Mitigation bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | Sep 29, 2026 |
| CVE-2026-100829 | UNKNOWN | — | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | Sep 29, 2026 |
| CVE-2026-100828 | UNKNOWN | — | Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | Sep 29, 2026 |
| CVE-2026-100826 | MEDIUM | 6.5 | Denial-of-service in the Storage: StorageManager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | Sep 29, 2026 |
| CVE-2026-100825 | HIGH | 8.8 | Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | Sep 29, 2026 |
| CVE-2026-100824 | HIGH | 8.8 | Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | Sep 29, 2026 |
| CVE-2026-100823 | UNKNOWN | — | Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157. | Sep 29, 2026 |
| CVE-2026-100822 | UNKNOWN | — | Spoofing issue in the Networking: HTTP component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157. | Sep 29, 2026 |
| CVE-2026-100821 | UNKNOWN | — | Site isolation issue in the Panning and Zooming component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR … | Sep 29, 2026 |
| CVE-2026-100820 | HIGH | 8.8 | Privilege escalation in the Address Bar component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. | Sep 29, 2026 |
| CVE-2026-100819 | CRITICAL | 9.6 | Sandbox escape due to incorrect boundary conditions in the XPCOM component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and … | Sep 29, 2026 |
| CVE-2026-100818 | CRITICAL | 9.6 | Sandbox escape due to use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. | Sep 29, 2026 |