Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41940
Total
3420
Critical
12400
High
12304
Medium
CVE ID Severity Score Description Published
CVE-2026-69857 HIGH 8.5 Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network. Sep 03, 2026
CVE-2026-65818 HIGH 8.5 Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network. Sep 03, 2026
CVE-2026-62916 CRITICAL 9.1 Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. Sep 03, 2026
CVE-2026-62906 HIGH 7.4 Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network. Sep 03, 2026
CVE-2026-18330 UNKNOWN A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may … Sep 03, 2026
CVE-2026-18167 UNKNOWN A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit … Sep 03, 2026
CVE-2026-85224 CRITICAL 9.1 A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a … Sep 03, 2026
CVE-2026-85223 CRITICAL 9.9 A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. … Sep 03, 2026
CVE-2026-64200 HIGH 7.8 There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a past the end of … Sep 03, 2026
CVE-2026-64199 HIGH 7.8 There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read outside the bounds of an … Sep 03, 2026
CVE-2026-64198 HIGH 7.8 There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a few bytes past the … Sep 03, 2026
CVE-2026-64197 HIGH 7.8 There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated … Sep 03, 2026
CVE-2026-64196 HIGH 7.8 There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated … Sep 03, 2026
CVE-2026-64195 HIGH 7.8 There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-supplied data. Successful exploitation requires an attacker to get a … Sep 03, 2026
CVE-2026-9745 MEDIUM 6.5 IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow … Sep 03, 2026
CVE-2026-9744 MEDIUM 5.3 IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive … Sep 03, 2026
CVE-2026-9736 MEDIUM 5.3 IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special … Sep 03, 2026
CVE-2026-9036 MEDIUM 5.9 IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive … Sep 03, 2026
CVE-2026-8862 HIGH 7.5 IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. … Sep 03, 2026
CVE-2026-85458 UNKNOWN Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height. Sep 03, 2026
CVE-2026-85222 CRITICAL 9.1 A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component Add-On … Sep 03, 2026
CVE-2026-85208 HIGH 7.3 A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. The affected element is the function doInsert of the file /rider/orders/controller.php?action=add of … Sep 03, 2026
CVE-2026-85063 UNKNOWN node-csv is a full-featured CSV parser with a simple API that is tested against large datasets. Prior to 7.0.2, csv-parse with the columns and group_columns_by_name … Sep 03, 2026
CVE-2026-85062 UNKNOWN Colord is a tiny yet powerful tool for high-performance color manipulations and conversions. Prior to 2.9.4, synchronous CSS color string matchers in src/colorModels/rgbString.ts, src/colorModels/hslString.ts, src/colorModels/hwbString.ts, … Sep 03, 2026
CVE-2026-85061 CRITICAL 10.0 MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap … Sep 03, 2026