Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41893
Total
3420
Critical
12384
High
12282
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-53603 | UNKNOWN | — | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions … | Sep 04, 2026 |
| CVE-2026-53602 | UNKNOWN | — | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host that should no … | Sep 04, 2026 |
| CVE-2026-85781 | HIGH | 8.7 | Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes … | Sep 04, 2026 |
| CVE-2026-85639 | MEDIUM | 5.6 | A security vulnerability has been detected in jofpin trape 2.0. This vulnerability affects unknown code of the file core/user.py of the component Telemetry Endpoint. Such … | Sep 04, 2026 |
| CVE-2026-85638 | HIGH | 7.3 | A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. This manipulation of the argument vId/id causes … | Sep 04, 2026 |
| CVE-2026-85637 | MEDIUM | 5.3 | A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affected by this issue is the function join_room of the file core/sockets.py of the component … | Sep 04, 2026 |
| CVE-2026-81939 | CRITICAL | 9.1 | A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside … | Sep 04, 2026 |
| CVE-2026-80119 | HIGH | 7.8 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that … | Sep 04, 2026 |
| CVE-2026-80118 | HIGH | 7.1 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, … | Sep 04, 2026 |
| CVE-2026-80117 | HIGH | 7.1 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that … | Sep 04, 2026 |
| CVE-2026-80116 | HIGH | 7.8 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that … | Sep 04, 2026 |
| CVE-2026-80115 | MEDIUM | 6.1 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation and denial-of-service vulnerability in … | Sep 04, 2026 |
| CVE-2026-80114 | HIGH | 7.8 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that … | Sep 04, 2026 |
| CVE-2026-80113 | HIGH | 7.1 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that … | Sep 04, 2026 |
| CVE-2026-80112 | HIGH | 7.8 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the … | Sep 04, 2026 |
| CVE-2026-78839 | UNKNOWN | — | An arbitrary file upload vulnerability in AppNitro MachForm v30 allows attackers to execute arbitrary code via uploading a crafted .phar file. | Sep 04, 2026 |
| CVE-2026-78328 | CRITICAL | 9.1 | A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin. | Sep 04, 2026 |
| CVE-2026-78327 | CRITICAL | 9.1 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface … | Sep 04, 2026 |
| CVE-2026-71620 | UNKNOWN | — | File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remote attacker to execute arbitrary code via a crafted .php file | Sep 04, 2026 |
| CVE-2026-9317 | HIGH | 8.1 | Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the … | Sep 04, 2026 |
| CVE-2026-85769 | MEDIUM | 6.5 | A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's … | Sep 04, 2026 |
| CVE-2026-85656 | HIGH | 7.8 | An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root … | Sep 04, 2026 |
| CVE-2026-85654 | HIGH | 7.8 | Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to … | Sep 04, 2026 |
| CVE-2026-85636 | MEDIUM | 5.3 | A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerability is an unknown functionality of the file core/stats.py of the component Login Endpoint. … | Sep 04, 2026 |
| CVE-2026-84890 | MEDIUM | 5.9 | undici's decompress interceptor decompresses response bodies according to the untrusted Content-Encoding header. While the number of content-encoding layers is capped, the total decompressed output size … | Sep 04, 2026 |