Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54298
Total
4306
Critical
16144
High
15836
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-95104 | HIGH | 7.5 | Stack-based buffer overflow vulnerability exists in BUFFALO Wi-Fi products. A non-authenticated crafted HTTP request may cause a denial-of-service (DoS) condition. | Sep 28, 2026 |
| CVE-2026-94287 | MEDIUM | 5.5 | A denial of service via unsigned underflow in libXpm's write path in libXpm before 3.5.19 could be used by local attackers to cause unbounded CPU … | Sep 28, 2026 |
| CVE-2026-94286 | HIGH | 7.1 | An out-of-bounds read in libXtst's RECORD reply parser in libXtst before 1.2.6 could be used by malicious X servers to crash attached X clients. | Sep 28, 2026 |
| CVE-2026-94285 | MEDIUM | 5.1 | An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients. | Sep 28, 2026 |
| CVE-2026-94284 | MEDIUM | 5.5 | An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X … | Sep 28, 2026 |
| CVE-2026-94283 | MEDIUM | 6.5 | An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash … | Sep 28, 2026 |
| CVE-2026-94282 | MEDIUM | 5.6 | An out-of-bounds read in libXi's XI2 enter/leave/focus cookie conversion in libXi before 1.8.4 could be used by malicious X server to crash an attached X … | Sep 28, 2026 |
| CVE-2026-86530 | HIGH | 7.2 | BUFFALO Wi-Fi products handle some web form input improperly to assemble command line strings internally. An administrative user may send a crafted HTTP request and … | Sep 28, 2026 |
| CVE-2026-86507 | MEDIUM | 6.1 | Improper neutralization of input in Apache Roller 6.1.5 allows an anonymous remote attacker to store a crafted comment-author URL that can execute script in the … | Sep 28, 2026 |
| CVE-2026-85134 | HIGH | 8.8 | Unrestricted upload of file with dangerous type vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows Upload a Web … | Sep 28, 2026 |
| CVE-2026-82969 | MEDIUM | 5.4 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System allows … | Sep 28, 2026 |
| CVE-2026-82915 | MEDIUM | 6.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bimser Solution Software Trade Inc. EBA Plus Document and Workflow Management System … | Sep 28, 2026 |
| CVE-2026-101017 | MEDIUM | 6.5 | A vulnerability was found in Trusted Domain Project OpenDMARC up to 1.4.2. This vulnerability affects the function strcasecmp in the library libopendmarc/opendmarc_policy.c. The manipulation results … | Sep 28, 2026 |
| CVE-2026-101016 | MEDIUM | 6.5 | A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_policy_parse_dmarc in the library libopendmarc/opendmarc_policy.c. The manipulation of … | Sep 28, 2026 |
| CVE-2026-101015 | HIGH | 7.3 | A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is some unknown functionality of the file policy.c … | Sep 28, 2026 |
| CVE-2026-101014 | HIGH | 7.3 | A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of … | Sep 28, 2026 |
| CVE-2026-91206 | MEDIUM | 6.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting through the … | Sep 28, 2026 |
| CVE-2026-91204 | MEDIUM | 6.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an anonymous remote attacker to store a comment containing a … | Sep 28, 2026 |
| CVE-2026-82546 | MEDIUM | 6.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows an unauthenticated remote attacker to store a crafted comment-author URL … | Sep 28, 2026 |
| CVE-2026-82387 | MEDIUM | 5.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a user with media-upload rights to store active content on … | Sep 28, 2026 |
| CVE-2026-82386 | HIGH | 7.7 | Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the Roller process and reach … | Sep 28, 2026 |
| CVE-2026-82385 | MEDIUM | 6.5 | Exposure of Sensitive Information to an Unauthorized Actor in Apache Roller 6.1.5 allows a weblog administrator to read files on the application classpath, including Roller … | Sep 28, 2026 |
| CVE-2026-82384 | CRITICAL | 9.8 | Deserialization of Untrusted Data in Apache Roller 6.1.5 allows an unauthenticated remote attacker to cause deserialization of attacker-controlled bytes, because the XML-RPC endpoint accepts vendor … | Sep 28, 2026 |
| CVE-2026-82383 | HIGH | 8.2 | Missing Authentication for Critical Function in Apache Roller 6.1.5 allows an unauthenticated remote attacker to persistently change a site-global configuration value (the frontpage weblog selection) … | Sep 28, 2026 |
| CVE-2026-82382 | MEDIUM | 6.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting against a … | Sep 28, 2026 |