Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41940
Total
3420
Critical
12400
High
12304
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-85184 | CRITICAL | 9.1 | @fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolves … | Sep 04, 2026 |
| CVE-2026-84504 | HIGH | 8.1 | fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If … | Sep 04, 2026 |
| CVE-2026-84469 | HIGH | 7.5 | fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines the boolean false as … | Sep 04, 2026 |
| CVE-2026-84044 | MEDIUM | 5.3 | The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment notification genuinely originates from PayPal, allowing unauthenticated attackers … | Sep 04, 2026 |
| CVE-2026-84043 | MEDIUM | 5.3 | The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark … | Sep 04, 2026 |
| CVE-2026-82923 | CRITICAL | 9.8 | The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers … | Sep 04, 2026 |
| CVE-2026-81666 | MEDIUM | 6.5 | An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems … | Sep 04, 2026 |
| CVE-2026-76169 | HIGH | 7.5 | fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different … | Sep 04, 2026 |
| CVE-2026-27086 | MEDIUM | 6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xtemos WoodMart allows DOM-Based XSS. This issue affects WoodMart: from n/a before 8.3.8. | Sep 04, 2026 |
| CVE-2026-13148 | UNKNOWN | — | Missing release of memory after effective lifetime vulnerability in Softing smartLink allows resource leak exposure. This issue affects smartLink HW-PN: from 1.04 before 1.10. | Sep 04, 2026 |
| CVE-2026-85538 | UNKNOWN | — | An incorrect authorization vulnerability in MISP allowed authenticated users to delete attributes from events despite lacking the required perm_modify or perm_modify_org permissions. The affected attribute … | Sep 04, 2026 |
| CVE-2026-85533 | UNKNOWN | — | An authorization flaw in MISP allowed an authenticated user to submit a sharing_group_id without verifying that the user was authorized to use the referenced Sharing … | Sep 04, 2026 |
| CVE-2026-85528 | MEDIUM | 5.3 | Improper input validation of the auto-configuration account identifier in Snowflake JDBC Driver versions 4.2.0 through 4.3.3 allowed a credential-bearing login request to be redirected to … | Sep 04, 2026 |
| CVE-2026-85525 | HIGH | 7.4 | Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP … | Sep 04, 2026 |
| CVE-2026-85311 | MEDIUM | 5.3 | Missing Authorization vulnerability in Kings Plugins MarketKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MarketKing: from n/a through 2.1.60. | Sep 04, 2026 |
| CVE-2026-81665 | HIGH | 7.5 | A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments … | Sep 04, 2026 |
| CVE-2026-81302 | HIGH | 7.8 | PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM privileges on the affected … | Sep 04, 2026 |
| CVE-2026-57777 | HIGH | 7.6 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooCommerce allows Blind SQL Injection. This issue affects WooCommerce: from … | Sep 04, 2026 |
| CVE-2026-32480 | MEDIUM | 5.3 | Missing Authorization vulnerability in WC Lovers WCFM Membership allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WCFM Membership: from n/a through 2.11.11. | Sep 04, 2026 |
| CVE-2026-27432 | MEDIUM | 5.4 | Authorization Bypass Through User-Controlled Key vulnerability in sc Internet Vivoo WP Rentals allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Rentals: … | Sep 04, 2026 |
| CVE-2026-15937 | UNKNOWN | — | Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID to reuse each other's mTLS certificate to … | Sep 04, 2026 |
| CVE-2026-85229 | UNKNOWN | — | ** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI. This issue affects Apache … | Sep 04, 2026 |
| CVE-2026-85197 | HIGH | 7.6 | A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client … | Sep 04, 2026 |
| CVE-2026-80190 | MEDIUM | 6.1 | Apache Allura: stored XSS via SVN code repositories. Git repositories are not known to be affected. The vulnerability is likely mitigated via default CSP headers. … | Sep 04, 2026 |
| CVE-2026-6217 | MEDIUM | 6.3 | Use of a One-Way hash without a salt vulnerability in Pik Online Software Solutions Inc. Pik Online Portal allows Cryptanalysis. This issue affects Pik Online … | Sep 04, 2026 |