Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41940
Total
3420
Critical
12400
High
12304
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-81292 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions. | Sep 03, 2026 |
| CVE-2026-81282 | MEDIUM | 6.5 | Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions. | Sep 03, 2026 |
| CVE-2026-81281 | MEDIUM | 6.5 | Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions. | Sep 03, 2026 |
| CVE-2026-75602 | MEDIUM | 6.5 | OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL … | Sep 03, 2026 |
| CVE-2026-85239 | UNKNOWN | — | A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template … | Sep 03, 2026 |
| CVE-2026-85238 | UNKNOWN | — | MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the … | Sep 03, 2026 |
| CVE-2026-85237 | UNKNOWN | — | A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint … | Sep 03, 2026 |
| CVE-2026-85236 | UNKNOWN | — | A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET … | Sep 03, 2026 |
| CVE-2026-85138 | HIGH | 7.3 | A vulnerability was detected in SeaCMS up to 13.6. Affected is the function addslashes of the file weixin/index.php of the component WeChat Module. The manipulation … | Sep 03, 2026 |
| CVE-2026-85137 | HIGH | 7.3 | A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. … | Sep 03, 2026 |
| CVE-2026-84967 | MEDIUM | 4.3 | A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into … | Sep 03, 2026 |
| CVE-2026-84966 | MEDIUM | 5.1 | An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. … | Sep 03, 2026 |
| CVE-2026-84965 | MEDIUM | 5.1 | An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following … | Sep 03, 2026 |
| CVE-2026-84964 | MEDIUM | 5.9 | A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the … | Sep 03, 2026 |
| CVE-2026-84963 | MEDIUM | 5.3 | An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be … | Sep 03, 2026 |
| CVE-2026-84962 | MEDIUM | 4.2 | An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized … | Sep 03, 2026 |
| CVE-2026-83961 | HIGH | 7.1 | ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain limited read and … | Sep 03, 2026 |
| CVE-2026-82525 | MEDIUM | 5.5 | Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by … | Sep 03, 2026 |
| CVE-2026-75036 | UNKNOWN | — | A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. … | Sep 03, 2026 |
| CVE-2026-75035 | HIGH | 7.7 | A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its … | Sep 03, 2026 |
| CVE-2026-75034 | HIGH | 7.4 | A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process … | Sep 03, 2026 |
| CVE-2026-71963 | HIGH | 8.8 | Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supplying … | Sep 03, 2026 |
| CVE-2026-57445 | UNKNOWN | — | Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In dfba919e218e20d52db9f7b2e8d292d45a46c91b … | Sep 03, 2026 |
| CVE-2026-55658 | HIGH | 7.7 | Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In 3e595f3 … | Sep 03, 2026 |
| CVE-2026-53924 | UNKNOWN | — | Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. Prior to … | Sep 03, 2026 |