Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41940
Total
3420
Critical
12400
High
12304
Medium
CVE ID Severity Score Description Published
CVE-2026-85394 CRITICAL 9.1 python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding … Sep 03, 2026
CVE-2026-85393 HIGH 7.5 node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the … Sep 03, 2026
CVE-2026-85392 MEDIUM 4.3 Peppermint through 0.5.5 contains an authorization bypass vulnerability in the GET /api/v1/auth/user/:id/logout endpoint that allows authenticated attackers to delete sessions for any user by supplying … Sep 03, 2026
CVE-2026-85391 CRITICAL 9.8 Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use … Sep 03, 2026
CVE-2026-85390 HIGH 7.1 Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attackers with user-role … Sep 03, 2026
CVE-2026-85389 MEDIUM 6.5 Worklenz before 3.0.0 fails to verify task ownership by organization when resolving task-scoped API endpoints, allowing authenticated users to access another tenant's task data. Attackers … Sep 03, 2026
CVE-2026-85388 HIGH 8.1 Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER … Sep 03, 2026
CVE-2026-85205 MEDIUM 6.3 A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addwishlist of the file /customer/controller.php?action=addwish of the component Wishlist. … Sep 03, 2026
CVE-2026-85028 HIGH 7.8 Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before … Sep 03, 2026
CVE-2026-82526 CRITICAL 9.8 R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in … Sep 03, 2026
CVE-2026-82302 HIGH 8.1 Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). Sep 03, 2026
CVE-2026-82299 MEDIUM 6.5 Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). Sep 03, 2026
CVE-2026-82298 MEDIUM 4.3 Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). Sep 03, 2026
CVE-2026-78596 MEDIUM 4.3 Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via Privilege … Sep 03, 2026
CVE-2026-78595 MEDIUM 4.3 Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privilege Abuse … Sep 03, 2026
CVE-2026-78593 MEDIUM 4.3 An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side … Sep 03, 2026
CVE-2026-78583 HIGH 8.1 Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not … Sep 03, 2026
CVE-2026-49456 LOW 3.1 Waku is the minimal React framework. Prior to version 1.0.0-beta.1, the unstable_redirect() helper exported from waku/router/server (packages/waku/src/router/define-router.tsx:156–161) accepts an arbitrary string and reflects it unchanged … Sep 03, 2026
CVE-2026-49455 MEDIUM 6.5 Waku is the minimal React framework. Prior to version 1.0.0-beta.1, Waku's RSC request dispatcher invokes server actions without validating the request's Origin (or Sec-Fetch-Site) header. … Sep 03, 2026
CVE-2026-33630 HIGH 7.5 c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's … Sep 03, 2026
CVE-2026-15431 UNKNOWN A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow a local attacker … Sep 03, 2026
CVE-2026-85187 HIGH 7.3 A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function Order::pupdate of the file /rider/orders/controller.php?action=edit&actions=confirm … Sep 03, 2026
CVE-2026-85012 HIGH 8.0 Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow … Sep 03, 2026
CVE-2026-84968 MEDIUM 5.3 An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have … Sep 03, 2026
CVE-2026-83959 HIGH 7.8 Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. … Sep 03, 2026