Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41940
Total
3420
Critical
12400
High
12304
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-85394 | CRITICAL | 9.1 | python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding … | Sep 03, 2026 |
| CVE-2026-85393 | HIGH | 7.5 | node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the … | Sep 03, 2026 |
| CVE-2026-85392 | MEDIUM | 4.3 | Peppermint through 0.5.5 contains an authorization bypass vulnerability in the GET /api/v1/auth/user/:id/logout endpoint that allows authenticated attackers to delete sessions for any user by supplying … | Sep 03, 2026 |
| CVE-2026-85391 | CRITICAL | 9.8 | Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use … | Sep 03, 2026 |
| CVE-2026-85390 | HIGH | 7.1 | Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attackers with user-role … | Sep 03, 2026 |
| CVE-2026-85389 | MEDIUM | 6.5 | Worklenz before 3.0.0 fails to verify task ownership by organization when resolving task-scoped API endpoints, allowing authenticated users to access another tenant's task data. Attackers … | Sep 03, 2026 |
| CVE-2026-85388 | HIGH | 8.1 | Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER … | Sep 03, 2026 |
| CVE-2026-85205 | MEDIUM | 6.3 | A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addwishlist of the file /customer/controller.php?action=addwish of the component Wishlist. … | Sep 03, 2026 |
| CVE-2026-85028 | HIGH | 7.8 | Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before … | Sep 03, 2026 |
| CVE-2026-82526 | CRITICAL | 9.8 | R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in … | Sep 03, 2026 |
| CVE-2026-82302 | HIGH | 8.1 | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). | Sep 03, 2026 |
| CVE-2026-82299 | MEDIUM | 6.5 | Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). | Sep 03, 2026 |
| CVE-2026-82298 | MEDIUM | 4.3 | Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). | Sep 03, 2026 |
| CVE-2026-78596 | MEDIUM | 4.3 | Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege … | Sep 03, 2026 |
| CVE-2026-78595 | MEDIUM | 4.3 | Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse … | Sep 03, 2026 |
| CVE-2026-78593 | MEDIUM | 4.3 | An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side … | Sep 03, 2026 |
| CVE-2026-78583 | HIGH | 8.1 | Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not … | Sep 03, 2026 |
| CVE-2026-49456 | LOW | 3.1 | Waku is the minimal React framework. Prior to version 1.0.0-beta.1, the unstable_redirect() helper exported from waku/router/server (packages/waku/src/router/define-router.tsx:156–161) accepts an arbitrary string and reflects it unchanged … | Sep 03, 2026 |
| CVE-2026-49455 | MEDIUM | 6.5 | Waku is the minimal React framework. Prior to version 1.0.0-beta.1, Waku's RSC request dispatcher invokes server actions without validating the request's Origin (or Sec-Fetch-Site) header. … | Sep 03, 2026 |
| CVE-2026-33630 | HIGH | 7.5 | c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's … | Sep 03, 2026 |
| CVE-2026-15431 | UNKNOWN | — | A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow a local attacker … | Sep 03, 2026 |
| CVE-2026-85187 | HIGH | 7.3 | A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function Order::pupdate of the file /rider/orders/controller.php?action=edit&actions=confirm … | Sep 03, 2026 |
| CVE-2026-85012 | HIGH | 8.0 | Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow … | Sep 03, 2026 |
| CVE-2026-84968 | MEDIUM | 5.3 | An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have … | Sep 03, 2026 |
| CVE-2026-83959 | HIGH | 7.8 | Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. … | Sep 03, 2026 |