Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42140
Total
3430
Critical
12454
High
12396
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-84233 | HIGH | 7.0 | A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated … | Sep 01, 2026 |
| CVE-2026-84115 | HIGH | 8.3 | A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT … | Sep 01, 2026 |
| CVE-2026-84114 | MEDIUM | 6.3 | A vulnerability has been found in Cleo Harmony up to 5.8.1.10. Impacted is the function LocalUserUtil.getNativeUserByAssertions of the component SAML Authentication. Such manipulation of the … | Sep 01, 2026 |
| CVE-2026-84111 | HIGH | 7.3 | A flaw has been found in Chanjet CRM up to 20260707. This issue affects some unknown processing of the file jxf_dump_table.php. This manipulation of the … | Sep 01, 2026 |
| CVE-2026-84110 | MEDIUM | 5.3 | A vulnerability was detected in Releasit Releasit COD Form & Upsells v1. This vulnerability affects unknown code of the component OTP Validation. The manipulation results … | Sep 01, 2026 |
| CVE-2026-83619 | UNKNOWN | — | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.7.0 until 0.8.15, the release-0.8.x parser in lib/sax.js … | Sep 01, 2026 |
| CVE-2026-83618 | UNKNOWN | — | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.10 until 0.9.12, the requireWellFormed: true serializer validates … | Sep 01, 2026 |
| CVE-2026-83617 | UNKNOWN | — | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.11 until 0.9.12, the requireWellFormed: true element and … | Sep 01, 2026 |
| CVE-2026-83616 | UNKNOWN | — | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in … | Sep 01, 2026 |
| CVE-2026-83615 | UNKNOWN | — | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in … | Sep 01, 2026 |
| CVE-2026-83614 | UNKNOWN | — | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in … | Sep 01, 2026 |
| CVE-2026-83613 | UNKNOWN | — | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in … | Sep 01, 2026 |
| CVE-2026-83612 | UNKNOWN | — | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.1 until 0.9.12, HTML-mode parsing through DOMParser.parseFromString() mishandles … | Sep 01, 2026 |
| CVE-2026-83611 | UNKNOWN | — | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in … | Sep 01, 2026 |
| CVE-2026-83610 | UNKNOWN | — | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in … | Sep 01, 2026 |
| CVE-2026-83609 | UNKNOWN | — | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0 until 0.9.12, the shared reg() builder in … | Sep 01, 2026 |
| CVE-2026-83608 | UNKNOWN | — | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in … | Sep 01, 2026 |
| CVE-2026-83607 | UNKNOWN | — | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.14 and 0.9.11, and in … | Sep 01, 2026 |
| CVE-2026-83606 | UNKNOWN | — | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.9 until 0.9.11, the processing-instruction production in lib/grammar.js … | Sep 01, 2026 |
| CVE-2026-83605 | UNKNOWN | — | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.14 and 0.9.11, and in … | Sep 01, 2026 |
| CVE-2026-83557 | MEDIUM | 5.6 | DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set … | Sep 01, 2026 |
| CVE-2026-79686 | HIGH | 8.8 | Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain … | Sep 01, 2026 |
| CVE-2026-79685 | MEDIUM | 6.5 | Dell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to gain unauthorized access to sensitive sensitive … | Sep 01, 2026 |
| CVE-2026-78012 | CRITICAL | 9.8 | An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without … | Sep 01, 2026 |
| CVE-2026-75538 | UNKNOWN | — | An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an … | Sep 01, 2026 |