Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54298
Total
4306
Critical
16144
High
15836
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-101916 | HIGH | 7.4 | @grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, getAuthContext does not distinguish authorized from … | Sep 28, 2026 |
| CVE-2026-101187 | CRITICAL | 9.1 | A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function pop_usb_device of the file usr/lib/lua/luci/controller/api/zrUsb.lua of the component USB Device … | Sep 28, 2026 |
| CVE-2026-101146 | MEDIUM | 4.3 | A security flaw has been discovered in Eleveo Quality Management 9.7.0. This issue affects the function UtilsService.createAndSaveAudit of the file /qm/cz.zoom.scorecard.webui.Scorecard/QMUtilsService of the component GWT … | Sep 28, 2026 |
| CVE-2026-101145 | MEDIUM | 4.3 | A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/userAddAction.do of the component User Management. Such … | Sep 28, 2026 |
| CVE-2026-101144 | MEDIUM | 6.3 | A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/searchAction.do of the component Query Builder. This … | Sep 28, 2026 |
| CVE-2026-100392 | UNKNOWN | — | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Users::form() performs no object-level authorization check on user_id = … | Sep 28, 2026 |
| CVE-2026-100371 | UNKNOWN | — | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, an authorization guard to Users::change_password(), was added to address … | Sep 28, 2026 |
| CVE-2026-100370 | MEDIUM | 4.7 | DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.15, the isDangerousUrl() method is responsible for rejecting dangerous URL values in the href … | Sep 28, 2026 |
| CVE-2026-96760 | UNKNOWN | — | Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully … | Sep 28, 2026 |
| CVE-2026-93355 | HIGH | 8.1 | LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user … | Sep 28, 2026 |
| CVE-2026-87741 | HIGH | 8.8 | The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of … | Sep 28, 2026 |
| CVE-2026-86950 | HIGH | 8.8 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe … | Sep 28, 2026 |
| CVE-2026-102004 | HIGH | 7.8 | Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in memory corruption within the memory management subsystem. Fixed in Version 26.09 | Sep 28, 2026 |
| CVE-2026-101915 | LOW | 3.7 | @grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1.14.5, when an application method handler throws … | Sep 28, 2026 |
| CVE-2026-101914 | MEDIUM | 6.5 | @grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1.14.1, the exact path (method name) matcher … | Sep 28, 2026 |
| CVE-2026-101143 | MEDIUM | 4.3 | A vulnerability was found in Eleveo Quality Management 9.7.0. Affected by this issue is some unknown functionality of the file /qm/cz.zoom.scorecard.webui.Scorecard/cz.zoom.scorecard.webui.Scorecard/QMBODownload. The manipulation results in … | Sep 28, 2026 |
| CVE-2026-101142 | MEDIUM | 6.3 | A vulnerability has been found in Eleveo Quality Management 9.7.0. Affected by this vulnerability is an unknown functionality of the file Scorecard.jsp of the component … | Sep 28, 2026 |
| CVE-2026-101141 | LOW | 3.5 | A flaw has been found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/audio.jsp of the component Play Audio … | Sep 28, 2026 |
| CVE-2026-97686 | MEDIUM | 5.5 | Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and … | Sep 28, 2026 |
| CVE-2026-97023 | HIGH | 7.1 | A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a malicious Flatpak app to cause deletion of attacker-chosen files … | Sep 28, 2026 |
| CVE-2026-84894 | UNKNOWN | — | In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the handle under proxygen's WebTransport API. A … | Sep 28, 2026 |
| CVE-2026-13018 | MEDIUM | 4.3 | Insufficient validation of untrusted input in Codecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially perform out of bounds memory access … | Sep 28, 2026 |
| CVE-2026-102010 | HIGH | 7.0 | A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage … | Sep 28, 2026 |
| CVE-2026-101139 | LOW | 2.7 | A vulnerability was detected in Webkul Bagisto up to 2.4.6. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status … | Sep 28, 2026 |
| CVE-2026-101132 | LOW | 3.1 | A security flaw has been discovered in DeepSeek deepseek-harness up to 0.1.7-rc.2. The affected element is the function loadProfile of the file packages/boot/app-boot/src/profile.ts of the … | Sep 28, 2026 |