Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54298
Total
4306
Critical
16144
High
15836
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-101131 | LOW | 3.3 | A vulnerability was identified in deepseek-ai deepseek-harness up to 0.1.5-rc.3. Impacted is an unknown function of the file packages/e2b/e2b/src/index.ts of the component dsh. The manipulation … | Sep 28, 2026 |
| CVE-2026-101111 | UNKNOWN | — | Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 - The public book-detail page template, site/views/view_book/tmpl/default.php, echoes the raw title … | Sep 28, 2026 |
| CVE-2026-101110 | UNKNOWN | — | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters … | Sep 28, 2026 |
| CVE-2026-101109 | UNKNOWN | — | Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8 - The public vehicle-detail page (task=view) echoes the title request parameter … | Sep 28, 2026 |
| CVE-2026-101108 | UNKNOWN | — | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and order_direction sort parameters at three … | Sep 28, 2026 |
| CVE-2026-101105 | MEDIUM | 6.3 | A vulnerability was determined in code-projects Matrimonial System 1.0. The affected element is the function processprofile_form of the file /create_profile of the component Profile Creation … | Sep 28, 2026 |
| CVE-2026-100753 | UNKNOWN | — | Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a review” form repopulates … | Sep 28, 2026 |
| CVE-2026-100752 | UNKNOWN | — | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate … | Sep 28, 2026 |
| CVE-2026-96740 | MEDIUM | 6.5 | A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api … | Sep 28, 2026 |
| CVE-2026-75600 | UNKNOWN | — | FreePBX is an open source IP PBX. Prior to version 17.0.9, authenticated users who are authorized to access the GraphQL api module interface of FreePBX … | Sep 28, 2026 |
| CVE-2026-55160 | HIGH | 7.6 | Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an unrestricted Server-Side Request Forgery (SSRF) vulnerability allows any authenticated user to force the … | Sep 28, 2026 |
| CVE-2026-55157 | HIGH | 8.4 | Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to … | Sep 28, 2026 |
| CVE-2026-55156 | MEDIUM | 5.3 | Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to … | Sep 28, 2026 |
| CVE-2026-54710 | UNKNOWN | — | FreePBX is an open source IP PBX. Prior to versions 16.0.40 and 17.0.7, a critical remote code execution (RCE) vulnerability exists in the superfecta module … | Sep 28, 2026 |
| CVE-2026-54708 | UNKNOWN | — | FreePBX is an open source IP PBX. Prior to versions 16.0.72 and 17.0.7, a critical vulnerability exists in the FreePBX backup Module that allows authenticated … | Sep 28, 2026 |
| CVE-2026-54675 | UNKNOWN | — | FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, a critical vulnerability exists in the sound language upload and conversion functionality … | Sep 28, 2026 |
| CVE-2026-54674 | UNKNOWN | — | FreePBX is an open source IP PBX. Prior to versions 16.0.39 and 17.0.7, users authenticated via User Control Panel (UCP) are able to execute arbitrary … | Sep 28, 2026 |
| CVE-2026-49994 | CRITICAL | 9.1 | Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML page handlers enforced session validation. The /api/* … | Sep 28, 2026 |
| CVE-2026-45562 | UNKNOWN | — | FreePBX is an open source IP PBX. Prior to versions 16.0.4 and 17.0.6, the FreePBX Music on Hold (MoH) module contains a critical security flaw … | Sep 28, 2026 |
| CVE-2026-101913 | UNKNOWN | — | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.5.1, the Address6 isLinkLocal method in src/ipv6.ts recognizes only … | Sep 28, 2026 |
| CVE-2026-101912 | UNKNOWN | — | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the isInSubnet and isHostInSubnet methods in src/common.ts compare … | Sep 28, 2026 |
| CVE-2026-101911 | UNKNOWN | — | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the Address6 constructor, Address6.isValid, and parse code in … | Sep 28, 2026 |
| CVE-2026-101910 | UNKNOWN | — | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.2.0 until 10.5.1, the Address6 isPrivate classifier in src/ipv6.ts does … | Sep 28, 2026 |
| CVE-2026-101909 | UNKNOWN | — | Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and … | Sep 28, 2026 |
| CVE-2026-101908 | UNKNOWN | — | Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs a Request with sanitized resolvedOptions but … | Sep 28, 2026 |