Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41893
Total
3420
Critical
12384
High
12282
Medium
CVE ID Severity Score Description Published
CVE-2026-80889 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: can: isotp: fix timer drain order, wakeup handling and tx_gen ordering This patch is a … Sep 04, 2026
CVE-2026-80888 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: drop dma_buf reference on foreign-fd prime import ttm_prime_fd_to_handle() returns -ENOSYS when the imported fd's … Sep 04, 2026
CVE-2026-80887 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: use check_add_overflow for shader size+offset bound vmw_shader_define() validates the user-supplied shader window against its … Sep 04, 2026
CVE-2026-73848 UNKNOWN Emlog is an open source website building system. In versions 2.6.29 and prior, tag names in emlog are not HTML-encoded when rendered in the article … Sep 04, 2026
CVE-2026-61688 MEDIUM 6.5 SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API request history of any other user's API tokens … Sep 04, 2026
CVE-2026-61686 HIGH 7.5 SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from … Sep 04, 2026
CVE-2026-61614 MEDIUM 5.9 SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tokens via a `?token=` URL query parameter as a … Sep 04, 2026
CVE-2026-61608 MEDIUM 6.8 SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, `UserInvitation` entities have no expiry timestamp. Invitation links mailed to users remain valid indefinitely, meaning … Sep 04, 2026
CVE-2026-57166 UNKNOWN PJSIP is a free and open source multimedia communication library written in C. Prior to commit 4472a31, a stack buffer overflow exists in the PJLIB-UTIL … Sep 04, 2026
CVE-2026-57165 UNKNOWN PJSIP is a free and open source multimedia communication library written in C. Prior to commit 628b716, a stack buffer overflow exists in the PJLIB-UTIL … Sep 04, 2026
CVE-2026-57164 UNKNOWN PJSIP is a free and open source multimedia communication library written in C. Prior to commit 8d5956a, a heap buffer overflow exists in the PJLIB-UTIL … Sep 04, 2026
CVE-2026-57163 UNKNOWN PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuTLS … Sep 04, 2026
CVE-2026-57162 UNKNOWN PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP/SDES … Sep 04, 2026
CVE-2026-57161 UNKNOWN PJSIP is a free and open source multimedia communication library written in C. Prior to commit acc03b5, a stack buffer overflow exists in PJSUA when … Sep 04, 2026
CVE-2026-57160 UNKNOWN PJSIP is a free and open source multimedia communication library written in C. Prior to commit d6a0e7f, a buffer overflow can occur in pjsip_generic_array_hdr_print() in … Sep 04, 2026
CVE-2026-57159 UNKNOWN PJSIP is a free and open source multimedia communication library written in C. Prior to commit 673b978, a remote out-of-bounds read and write can occur … Sep 04, 2026
CVE-2026-53761 UNKNOWN Frappe CRM is an open-source customer relationship management tool. Prior to version 1.73.0, there is an authentication bypass vulnerability via logged invitation keys in crm/api. … Sep 04, 2026
CVE-2026-53760 MEDIUM 5.2 Admidio is an open-source user management solution. In versions 5.0.11 and prior, the modules/plugins.php endpoint handles plugin installation, uninstallation, and update operations via GET requests … Sep 04, 2026
CVE-2026-53758 UNKNOWN Emlog is an open source website building system. In versions 2.6.29 and prior, article content is processed by Parsedown without enabling safe mode, which means … Sep 04, 2026
CVE-2026-53757 UNKNOWN Emlog is an open source website building system. In versions 2.6.29 and prior, the emUnZip() function extracts all ZIP entries via ZipArchive::extractTo() without validating entry … Sep 04, 2026
CVE-2026-53756 MEDIUM 4.9 Emlog is an open source website building system. Prior to version 2.6.16, Emlog CMS Pro contains a blind SQL injection in User_Model::getUserDataByLogin(). The $account parameter … Sep 04, 2026
CVE-2026-50553 UNKNOWN Note Mark is an open-source note-taking application. Prior to version 0.19.5, Note Mark validates book and note slug values with the OpenAPI/huma tag pattern:"[a-z0-9-]+". huma … Sep 04, 2026
CVE-2026-19534 HIGH 7.5 undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A … Sep 04, 2026
CVE-2026-18745 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Sep 04, 2026
CVE-2026-18540 LOW 3.7 undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the … Sep 04, 2026