Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41893
Total
3420
Critical
12384
High
12282
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-80889 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: can: isotp: fix timer drain order, wakeup handling and tx_gen ordering This patch is a … | Sep 04, 2026 |
| CVE-2026-80888 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: drop dma_buf reference on foreign-fd prime import ttm_prime_fd_to_handle() returns -ENOSYS when the imported fd's … | Sep 04, 2026 |
| CVE-2026-80887 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: use check_add_overflow for shader size+offset bound vmw_shader_define() validates the user-supplied shader window against its … | Sep 04, 2026 |
| CVE-2026-73848 | UNKNOWN | — | Emlog is an open source website building system. In versions 2.6.29 and prior, tag names in emlog are not HTML-encoded when rendered in the article … | Sep 04, 2026 |
| CVE-2026-61688 | MEDIUM | 6.5 | SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API request history of any other user's API tokens … | Sep 04, 2026 |
| CVE-2026-61686 | HIGH | 7.5 | SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from … | Sep 04, 2026 |
| CVE-2026-61614 | MEDIUM | 5.9 | SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tokens via a `?token=` URL query parameter as a … | Sep 04, 2026 |
| CVE-2026-61608 | MEDIUM | 6.8 | SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, `UserInvitation` entities have no expiry timestamp. Invitation links mailed to users remain valid indefinitely, meaning … | Sep 04, 2026 |
| CVE-2026-57166 | UNKNOWN | — | PJSIP is a free and open source multimedia communication library written in C. Prior to commit 4472a31, a stack buffer overflow exists in the PJLIB-UTIL … | Sep 04, 2026 |
| CVE-2026-57165 | UNKNOWN | — | PJSIP is a free and open source multimedia communication library written in C. Prior to commit 628b716, a stack buffer overflow exists in the PJLIB-UTIL … | Sep 04, 2026 |
| CVE-2026-57164 | UNKNOWN | — | PJSIP is a free and open source multimedia communication library written in C. Prior to commit 8d5956a, a heap buffer overflow exists in the PJLIB-UTIL … | Sep 04, 2026 |
| CVE-2026-57163 | UNKNOWN | — | PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuTLS … | Sep 04, 2026 |
| CVE-2026-57162 | UNKNOWN | — | PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP/SDES … | Sep 04, 2026 |
| CVE-2026-57161 | UNKNOWN | — | PJSIP is a free and open source multimedia communication library written in C. Prior to commit acc03b5, a stack buffer overflow exists in PJSUA when … | Sep 04, 2026 |
| CVE-2026-57160 | UNKNOWN | — | PJSIP is a free and open source multimedia communication library written in C. Prior to commit d6a0e7f, a buffer overflow can occur in pjsip_generic_array_hdr_print() in … | Sep 04, 2026 |
| CVE-2026-57159 | UNKNOWN | — | PJSIP is a free and open source multimedia communication library written in C. Prior to commit 673b978, a remote out-of-bounds read and write can occur … | Sep 04, 2026 |
| CVE-2026-53761 | UNKNOWN | — | Frappe CRM is an open-source customer relationship management tool. Prior to version 1.73.0, there is an authentication bypass vulnerability via logged invitation keys in crm/api. … | Sep 04, 2026 |
| CVE-2026-53760 | MEDIUM | 5.2 | Admidio is an open-source user management solution. In versions 5.0.11 and prior, the modules/plugins.php endpoint handles plugin installation, uninstallation, and update operations via GET requests … | Sep 04, 2026 |
| CVE-2026-53758 | UNKNOWN | — | Emlog is an open source website building system. In versions 2.6.29 and prior, article content is processed by Parsedown without enabling safe mode, which means … | Sep 04, 2026 |
| CVE-2026-53757 | UNKNOWN | — | Emlog is an open source website building system. In versions 2.6.29 and prior, the emUnZip() function extracts all ZIP entries via ZipArchive::extractTo() without validating entry … | Sep 04, 2026 |
| CVE-2026-53756 | MEDIUM | 4.9 | Emlog is an open source website building system. Prior to version 2.6.16, Emlog CMS Pro contains a blind SQL injection in User_Model::getUserDataByLogin(). The $account parameter … | Sep 04, 2026 |
| CVE-2026-50553 | UNKNOWN | — | Note Mark is an open-source note-taking application. Prior to version 0.19.5, Note Mark validates book and note slug values with the OpenAPI/huma tag pattern:"[a-z0-9-]+". huma … | Sep 04, 2026 |
| CVE-2026-19534 | HIGH | 7.5 | undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A … | Sep 04, 2026 |
| CVE-2026-18745 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 04, 2026 |
| CVE-2026-18540 | LOW | 3.7 | undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the … | Sep 04, 2026 |