Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41940
Total
3420
Critical
12400
High
12304
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-69857 | HIGH | 8.5 | Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network. | Sep 03, 2026 |
| CVE-2026-65818 | HIGH | 8.5 | Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network. | Sep 03, 2026 |
| CVE-2026-62916 | CRITICAL | 9.1 | Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. | Sep 03, 2026 |
| CVE-2026-62906 | HIGH | 7.4 | Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network. | Sep 03, 2026 |
| CVE-2026-18330 | UNKNOWN | — | A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may … | Sep 03, 2026 |
| CVE-2026-18167 | UNKNOWN | — | A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit … | Sep 03, 2026 |
| CVE-2026-85224 | CRITICAL | 9.1 | A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a … | Sep 03, 2026 |
| CVE-2026-85223 | CRITICAL | 9.9 | A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. … | Sep 03, 2026 |
| CVE-2026-64200 | HIGH | 7.8 | There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a past the end of … | Sep 03, 2026 |
| CVE-2026-64199 | HIGH | 7.8 | There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read outside the bounds of an … | Sep 03, 2026 |
| CVE-2026-64198 | HIGH | 7.8 | There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a few bytes past the … | Sep 03, 2026 |
| CVE-2026-64197 | HIGH | 7.8 | There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated … | Sep 03, 2026 |
| CVE-2026-64196 | HIGH | 7.8 | There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated … | Sep 03, 2026 |
| CVE-2026-64195 | HIGH | 7.8 | There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-supplied data. Successful exploitation requires an attacker to get a … | Sep 03, 2026 |
| CVE-2026-9745 | MEDIUM | 6.5 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow … | Sep 03, 2026 |
| CVE-2026-9744 | MEDIUM | 5.3 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive … | Sep 03, 2026 |
| CVE-2026-9736 | MEDIUM | 5.3 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special … | Sep 03, 2026 |
| CVE-2026-9036 | MEDIUM | 5.9 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive … | Sep 03, 2026 |
| CVE-2026-8862 | HIGH | 7.5 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. … | Sep 03, 2026 |
| CVE-2026-85458 | UNKNOWN | — | Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height. | Sep 03, 2026 |
| CVE-2026-85222 | CRITICAL | 9.1 | A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component Add-On … | Sep 03, 2026 |
| CVE-2026-85208 | HIGH | 7.3 | A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. The affected element is the function doInsert of the file /rider/orders/controller.php?action=add of … | Sep 03, 2026 |
| CVE-2026-85063 | UNKNOWN | — | node-csv is a full-featured CSV parser with a simple API that is tested against large datasets. Prior to 7.0.2, csv-parse with the columns and group_columns_by_name … | Sep 03, 2026 |
| CVE-2026-85062 | UNKNOWN | — | Colord is a tiny yet powerful tool for high-performance color manipulations and conversions. Prior to 2.9.4, synchronous CSS color string matchers in src/colorModels/rgbString.ts, src/colorModels/hslString.ts, src/colorModels/hwbString.ts, … | Sep 03, 2026 |
| CVE-2026-85061 | CRITICAL | 10.0 | MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap … | Sep 03, 2026 |