Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54298
Total
4306
Critical
16144
High
15836
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-101266 | UNKNOWN | — | A logic flaw in the checkout flow allows users to bypass validations performed during the check-in by skipping entire check-in steps. | Sep 29, 2026 |
| CVE-2026-95509 | UNKNOWN | — | Strings optimized for Latin-1 displaying Latin-1 characters cause incorrect String.arg() formatting by an incorrect buffer size calculation, causing out-of-bounds reading. | Sep 29, 2026 |
| CVE-2026-96423 | MEDIUM | 5.5 | X11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | Sep 29, 2026 |
| CVE-2026-96422 | MEDIUM | 5.5 | Frame protocol metadissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | Sep 29, 2026 |
| CVE-2026-96421 | MEDIUM | 5.5 | USB HID protocol dissector infinite loop and memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | Sep 29, 2026 |
| CVE-2026-96420 | MEDIUM | 4.7 | Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | Sep 29, 2026 |
| CVE-2026-96419 | MEDIUM | 5.5 | Profile import crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service and possible code execution | Sep 29, 2026 |
| CVE-2026-96418 | MEDIUM | 5.5 | TIFF protocol dissector infinite loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | Sep 29, 2026 |
| CVE-2026-96417 | MEDIUM | 5.5 | RF4CE protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | Sep 29, 2026 |
| CVE-2026-96416 | MEDIUM | 5.5 | IEEE 802.11 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | Sep 29, 2026 |
| CVE-2026-96415 | MEDIUM | 5.5 | Catapult DCT2000 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | Sep 29, 2026 |
| CVE-2026-95395 | MEDIUM | 5.5 | IEEE C37.118 Synchrophasor protocol dissector memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | Sep 29, 2026 |
| CVE-2026-95394 | MEDIUM | 4.7 | Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | Sep 29, 2026 |
| CVE-2026-95393 | MEDIUM | 4.7 | CSN.1 protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | Sep 29, 2026 |
| CVE-2026-95392 | MEDIUM | 5.5 | MBIM protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | Sep 29, 2026 |
| CVE-2026-95391 | MEDIUM | 5.5 | ZigBee ZCL protocol dissector crash in 4.6.0 to 4.6.8 allows denial of service | Sep 29, 2026 |
| CVE-2026-95390 | MEDIUM | 5.5 | PEAK CAN TRC file parser crash in 4.6.0 to 4.6.8 allows denial of service | Sep 29, 2026 |
| CVE-2026-95389 | HIGH | 8.1 | SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | Sep 29, 2026 |
| CVE-2026-95388 | MEDIUM | 5.5 | Sharkd utility crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | Sep 29, 2026 |
| CVE-2026-95387 | HIGH | 8.1 | SPDY protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | Sep 29, 2026 |
| CVE-2026-95386 | MEDIUM | 5.5 | TTL file parser infinite loop in 4.6.0 to 4.6.8 allows denial of service | Sep 29, 2026 |
| CVE-2026-8937 | MEDIUM | 4.3 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain … | Sep 29, 2026 |
| CVE-2026-8067 | MEDIUM | 6.5 | An improper authorization vulnerability in the end-of-life versions of RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset … | Sep 29, 2026 |
| CVE-2026-8066 | CRITICAL | 9.1 | A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to write or overwrite arbitrary files … | Sep 29, 2026 |
| CVE-2026-8065 | CRITICAL | 9.1 | An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated attacker to upload arbitrary firmware through a … | Sep 29, 2026 |