Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54298
Total
4306
Critical
16144
High
15836
Medium
CVE ID Severity Score Description Published
CVE-2026-95104 HIGH 7.5 Stack-based buffer overflow vulnerability exists in BUFFALO Wi-Fi products. A non-authenticated crafted HTTP request may cause a denial-of-service (DoS) condition. Sep 28, 2026
CVE-2026-94287 MEDIUM 5.5 A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU … Sep 28, 2026
CVE-2026-94286 HIGH 7.1 An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients. Sep 28, 2026
CVE-2026-94285 MEDIUM 5.1 An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients. Sep 28, 2026
CVE-2026-94284 MEDIUM 5.5 An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X … Sep 28, 2026
CVE-2026-94283 MEDIUM 6.5 An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash … Sep 28, 2026
CVE-2026-94282 MEDIUM 5.6 An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X … Sep 28, 2026
CVE-2026-86530 HIGH 7.2 BUFFALO Wi-Fi products handle some web form input improperly to assemble command line strings internally. An administrative user may send a crafted HTTP request and … Sep 28, 2026
CVE-2026-86507 MEDIUM 6.1 Improper neutralization of input in Apache Roller 6.1.5 allows an anonymous remote attacker to store a crafted comment-author URL that can execute script in the … Sep 28, 2026
CVE-2026-85134 HIGH 8.8 Unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Upload a Web … Sep 28, 2026
CVE-2026-82969 MEDIUM 5.4 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows … Sep 28, 2026
CVE-2026-82915 MEDIUM 6.5 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System … Sep 28, 2026
CVE-2026-101017 MEDIUM 6.5 A vulnerability was found in Trusted Domain Project OpenDMARC up to 1.4.2. This vulnerability affects the function strcasecmp in the library libopendmarc/opendmarc_policy.c. The manipulation results … Sep 28, 2026
CVE-2026-101016 MEDIUM 6.5 A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_policy_parse_dmarc in the library libopendmarc/opendmarc_policy.c. The manipulation of … Sep 28, 2026
CVE-2026-101015 HIGH 7.3 A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is some unknown functionality of the file policy.c … Sep 28, 2026
CVE-2026-101014 HIGH 7.3 A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of … Sep 28, 2026
CVE-2026-91206 MEDIUM 6.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting through the … Sep 28, 2026
CVE-2026-91204 MEDIUM 6.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an anonymous remote attacker to store a comment containing a … Sep 28, 2026
CVE-2026-82546 MEDIUM 6.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an unauthenticated remote attacker to store a crafted comment-author URL … Sep 28, 2026
CVE-2026-82387 MEDIUM 5.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with media-upload rights to store active content on … Sep 28, 2026
CVE-2026-82386 HIGH 7.7 Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the Roller process and reach … Sep 28, 2026
CVE-2026-82385 MEDIUM 6.5 Exposure of Sensitive Information to an Unauthorized Actor in Apache Roller 6.1.5 allows a weblog administrator to read files on the application classpath, including Roller … Sep 28, 2026
CVE-2026-82384 CRITICAL 9.8 Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor … Sep 28, 2026
CVE-2026-82383 HIGH 8.2 Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote attacker to persistently change a site-global configuration value (the frontpage weblog selection) … Sep 28, 2026
CVE-2026-82382 MEDIUM 6.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting against a … Sep 28, 2026