Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54298
Total
4306
Critical
16144
High
15836
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-84154 | CRITICAL | 9.9 | A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code … | Sep 29, 2026 |
| CVE-2026-101169 | UNKNOWN | — | In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can set specifically crafted JSON content for the … | Sep 29, 2026 |
| CVE-2026-86158 | HIGH | 7.7 | Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a local unauthenticated attacker to mint OAuth tokens and read … | Sep 29, 2026 |
| CVE-2026-86157 | MEDIUM | 5.6 | Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low-privileged attacker who can modify application launch parameters and … | Sep 29, 2026 |
| CVE-2026-102293 | HIGH | 7.3 | A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.add of the file ApiMaApplication.java of the component api-admin Backend. The manipulation of … | Sep 29, 2026 |
| CVE-2026-102292 | MEDIUM | 4.3 | A flaw has been found in coolbeans1212 MateisHomePage-Website up to ea2a4226deeca27ab1fb9df0552ec76444547811. Affected by this issue is some unknown functionality of the file users.php. This manipulation … | Sep 29, 2026 |
| CVE-2026-102290 | LOW | 3.5 | A vulnerability was determined in CodeCanyon Rocket LMS up to 2.2. This affects an unknown function of the component Student Profile Image Upload. Executing a … | Sep 29, 2026 |
| CVE-2026-102264 | LOW | 3.5 | A vulnerability was found in mwasikz robo-cafe-rms up to 228c44a02823f04e85db32b7137809a2856148fc. The impacted element is an unknown function of the file frontend/update-account.php of the component Edit … | Sep 29, 2026 |
| CVE-2026-102263 | MEDIUM | 4.7 | A vulnerability has been found in mwasikz robo-cafe-rms up to 228c44a02823f04e85db32b7137809a2856148fc. The affected element is an unknown function of the file manage-food.php. Such manipulation leads … | Sep 29, 2026 |
| CVE-2026-102261 | MEDIUM | 5.4 | A flaw has been found in owen2345 Camaleon CMS up to 2.9.2. Impacted is the function crop of the file app/controllers/camaleon_cms/admin/media_controller.rb of the component Media … | Sep 29, 2026 |
| CVE-2026-97029 | MEDIUM | 5.7 | Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share … | Sep 29, 2026 |
| CVE-2026-97024 | HIGH | 7.1 | A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certain host system files … | Sep 29, 2026 |
| CVE-2026-102422 | HIGH | 8.1 | shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the shell line, including … | Sep 29, 2026 |
| CVE-2026-102414 | LOW | 3.7 | pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block … | Sep 29, 2026 |
| CVE-2026-102249 | HIGH | 7.3 | A security flaw has been discovered in REBUILD up to 4.4.11. This vulnerability affects unknown code of the file /commons/file-editor-save. The manipulation of the argument … | Sep 29, 2026 |
| CVE-2026-102248 | HIGH | 7.3 | A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login of the component Login Endpoint. The manipulation … | Sep 29, 2026 |
| CVE-2026-102247 | MEDIUM | 6.8 | A vulnerability was detected in FastAdmin 1.6.1.20250430/1.6.5.20260602. This affects an unknown function of the file application/database.php of the component Database Management. The manipulation results in … | Sep 29, 2026 |
| CVE-2026-102245 | HIGH | 7.3 | A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component … | Sep 29, 2026 |
| CVE-2026-97685 | UNKNOWN | — | An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an authorized context while supplying question or answer … | Sep 29, 2026 |
| CVE-2026-102244 | MEDIUM | 4.3 | A security flaw has been discovered in MODSetter SurfSense up to 0.0.36. Impacted is an unknown function of the file surfsense_backend/app/routes/editor_routes.py of the component Document … | Sep 29, 2026 |
| CVE-2026-102243 | HIGH | 7.4 | A vulnerability was identified in MODSetter SurfSense up to 2.0.3. This issue affects some unknown processing of the file /api/search-source/connectors/mcp/test of the component MCP Connector … | Sep 29, 2026 |
| CVE-2026-102241 | LOW | 2.7 | A vulnerability was determined in Netcore NAP930 0.1.241010.141410. This vulnerability affects unknown code of the file /lib/functions/backup_common.sh of the component Backup/Restore. This manipulation of the … | Sep 29, 2026 |
| CVE-2026-96326 | HIGH | 7.2 | The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text … | Sep 29, 2026 |
| CVE-2026-102240 | CRITICAL | 10.0 | A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation … | Sep 29, 2026 |
| CVE-2026-101878 | HIGH | 7.5 | Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating … | Sep 29, 2026 |