Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41940
Total
3420
Critical
12400
High
12304
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-84970 | MEDIUM | 6.2 | A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who controls the text that an … | Sep 03, 2026 |
| CVE-2026-84969 | LOW | 3.7 | A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a … | Sep 03, 2026 |
| CVE-2026-75033 | HIGH | 7.7 | A flaw was found in Rancher Manager. Project Secrets were propagated into a namespace based only on its `field.cattle.io/projectId` annotation, without verifying that the referenced … | Sep 03, 2026 |
| CVE-2026-71404 | HIGH | 8.7 | A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object's rules … | Sep 03, 2026 |
| CVE-2026-71403 | MEDIUM | 6.1 | A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and `principalIds` fields. A user … | Sep 03, 2026 |
| CVE-2026-63694 | MEDIUM | 5.0 | Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged … | Sep 03, 2026 |
| CVE-2026-56128 | MEDIUM | 5.4 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Schedules: Edit privilege to inject arbitrary JavaScript via the descr parameter … | Sep 03, 2026 |
| CVE-2026-56127 | MEDIUM | 5.4 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Rules: Edit privilege to inject arbitrary JavaScript via the descr parameter … | Sep 03, 2026 |
| CVE-2026-56126 | MEDIUM | 5.4 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Status: Monitoring privilege to inject arbitrary JavaScript via graph configuration parameters in … | Sep 03, 2026 |
| CVE-2026-35160 | MEDIUM | 5.0 | Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A … | Sep 03, 2026 |
| CVE-2026-85110 | HIGH | 8.8 | A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manipulation … | Sep 03, 2026 |
| CVE-2026-85109 | CRITICAL | 9.8 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing … | Sep 03, 2026 |
| CVE-2026-84815 | MEDIUM | 5.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold allows Reflected XSS. This issue affects Enfold: from n/a through 8.0. | Sep 03, 2026 |
| CVE-2026-82180 | UNKNOWN | — | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, CertificateMqttFilter parses an X.509 certificate that … | Sep 03, 2026 |
| CVE-2026-80515 | UNKNOWN | — | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling … | Sep 03, 2026 |
| CVE-2026-6071 | UNKNOWN | — | A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the … | Sep 03, 2026 |
| CVE-2025-12737 | HIGH | 8.4 | The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject … | Sep 03, 2026 |
| CVE-2026-9854 | UNKNOWN | — | A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying … | Sep 03, 2026 |
| CVE-2026-9853 | UNKNOWN | — | A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application … | Sep 03, 2026 |
| CVE-2026-9852 | UNKNOWN | — | A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some … | Sep 03, 2026 |
| CVE-2026-85175 | HIGH | 8.8 | SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.json by exact match and does … | Sep 03, 2026 |
| CVE-2026-85174 | HIGH | 8.8 | SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers … | Sep 03, 2026 |
| CVE-2026-85173 | UNKNOWN | — | n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow … | Sep 03, 2026 |
| CVE-2026-85172 | UNKNOWN | — | n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper function exposed to Code and Function nodes. The validation logic … | Sep 03, 2026 |
| CVE-2026-85171 | UNKNOWN | — | n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailcheck nodes. These nodes send their decrypted credentials to … | Sep 03, 2026 |