Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41987
Total
3420
Critical
12405
High
12324
Medium
CVE ID Severity Score Description Published
CVE-2026-71404 HIGH 8.7 A flaw was found in Rancher Manager. The GlobalRole controller derived the target ClusterRole name from the user-settable `authz.management.cattle.io/cr-name` annotation and overwrote that object's rules … Sep 03, 2026
CVE-2026-71403 MEDIUM 6.1 A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `username` and `principalIds` fields. A user … Sep 03, 2026
CVE-2026-63694 MEDIUM 5.0 Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged … Sep 03, 2026
CVE-2026-56128 MEDIUM 5.4 pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Schedules: Edit privilege to inject arbitrary JavaScript via the descr parameter … Sep 03, 2026
CVE-2026-56127 MEDIUM 5.4 pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Rules: Edit privilege to inject arbitrary JavaScript via the descr parameter … Sep 03, 2026
CVE-2026-56126 MEDIUM 5.4 pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Status: Monitoring privilege to inject arbitrary JavaScript via graph configuration parameters in … Sep 03, 2026
CVE-2026-35160 MEDIUM 5.0 Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A … Sep 03, 2026
CVE-2026-85110 HIGH 8.8 A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manipulation … Sep 03, 2026
CVE-2026-85109 CRITICAL 9.8 A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing … Sep 03, 2026
CVE-2026-84815 MEDIUM 5.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold allows Reflected XSS. This issue affects Enfold: from n/a through 8.0. Sep 03, 2026
CVE-2026-82180 UNKNOWN In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, CertificateMqttFilter parses an X.509 certificate that … Sep 03, 2026
CVE-2026-80515 UNKNOWN In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling … Sep 03, 2026
CVE-2026-6071 UNKNOWN A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the … Sep 03, 2026
CVE-2025-12737 HIGH 8.4 The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject … Sep 03, 2026
CVE-2026-9854 UNKNOWN A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying … Sep 03, 2026
CVE-2026-9853 UNKNOWN A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application … Sep 03, 2026
CVE-2026-9852 UNKNOWN A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some … Sep 03, 2026
CVE-2026-85175 HIGH 8.8 SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which only blocks conf/conf.json by exact match and does … Sep 03, 2026
CVE-2026-85174 HIGH 8.8 SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers … Sep 03, 2026
CVE-2026-85173 UNKNOWN n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow … Sep 03, 2026
CVE-2026-85172 UNKNOWN n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper function exposed to Code and Function nodes. The validation logic … Sep 03, 2026
CVE-2026-85171 UNKNOWN n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailcheck nodes. These nodes send their decrypted credentials to … Sep 03, 2026
CVE-2026-85170 UNKNOWN n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail composer without verifying it is … Sep 03, 2026
CVE-2026-85169 UNKNOWN n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox escape in the $fromAI handler. $fromAI resolved a caller-supplied placeholder name without requiring it … Sep 03, 2026
CVE-2026-85168 UNKNOWN n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code execution vulnerability in the Git node. The node reset a fixed list of command-bearing … Sep 03, 2026