Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41893
Total
3420
Critical
12384
High
12282
Medium
CVE ID Severity Score Description Published
CVE-2026-53603 UNKNOWN nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions … Sep 04, 2026
CVE-2026-53602 UNKNOWN nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host that should no … Sep 04, 2026
CVE-2026-85781 HIGH 8.7 Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes … Sep 04, 2026
CVE-2026-85639 MEDIUM 5.6 A security vulnerability has been detected in jofpin trape 2.0. This vulnerability affects unknown code of the file core/user.py of the component Telemetry Endpoint. Such … Sep 04, 2026
CVE-2026-85638 HIGH 7.3 A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. This manipulation of the argument vId/id causes … Sep 04, 2026
CVE-2026-85637 MEDIUM 5.3 A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affected by this issue is the function join_room of the file core/sockets.py of the component … Sep 04, 2026
CVE-2026-81939 CRITICAL 9.1 A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside … Sep 04, 2026
CVE-2026-80119 HIGH 7.8 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that … Sep 04, 2026
CVE-2026-80118 HIGH 7.1 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, … Sep 04, 2026
CVE-2026-80117 HIGH 7.1 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that … Sep 04, 2026
CVE-2026-80116 HIGH 7.8 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that … Sep 04, 2026
CVE-2026-80115 MEDIUM 6.1 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation and denial-of-service vulnerability in … Sep 04, 2026
CVE-2026-80114 HIGH 7.8 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that … Sep 04, 2026
CVE-2026-80113 HIGH 7.1 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that … Sep 04, 2026
CVE-2026-80112 HIGH 7.8 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the … Sep 04, 2026
CVE-2026-78839 UNKNOWN An arbitrary file upload vulnerability in AppNitro MachForm v30 allows attackers to execute arbitrary code via uploading a crafted .phar file. Sep 04, 2026
CVE-2026-78328 CRITICAL 9.1 A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin. Sep 04, 2026
CVE-2026-78327 CRITICAL 9.1 An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface … Sep 04, 2026
CVE-2026-71620 UNKNOWN File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remote attacker to execute arbitrary code via a crafted .php file Sep 04, 2026
CVE-2026-9317 HIGH 8.1 Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the … Sep 04, 2026
CVE-2026-85769 MEDIUM 6.5 A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's … Sep 04, 2026
CVE-2026-85656 HIGH 7.8 An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root … Sep 04, 2026
CVE-2026-85654 HIGH 7.8 Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to … Sep 04, 2026
CVE-2026-85636 MEDIUM 5.3 A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerability is an unknown functionality of the file core/stats.py of the component Login Endpoint. … Sep 04, 2026
CVE-2026-84890 MEDIUM 5.9 undici's decompress interceptor decompresses response bodies according to the untrusted Content-Encoding header. While the number of content-encoding layers is capped, the total decompressed output size … Sep 04, 2026