Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41893
Total
3420
Critical
12384
High
12282
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-52772 | MEDIUM | 5.5 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field.label / field.hint in attribute and … | Sep 05, 2026 |
| CVE-2026-52771 | HIGH | 8.3 | YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a page tag retrieved from the database into … | Sep 05, 2026 |
| CVE-2026-52770 | HIGH | 7.5 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthenticated SQL injection in numeric … | Sep 05, 2026 |
| CVE-2026-52769 | HIGH | 8.3 | YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route - exposed publicly with acl:"public" - … | Sep 05, 2026 |
| CVE-2026-52767 | HIGH | 8.2 | YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() with a loose … | Sep 05, 2026 |
| CVE-2026-52766 | CRITICAL | 9.1 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes … | Sep 05, 2026 |
| CVE-2026-52763 | MEDIUM | 6.5 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the recentchanges action (actions/recentchanges.php) accepts a period argument from two disjoint parameter spaces. … | Sep 05, 2026 |
| CVE-2026-52762 | UNKNOWN | — | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) vulnerability in the semantic … | Sep 05, 2026 |
| CVE-2026-86098 | HIGH | 7.4 | ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the … | Sep 04, 2026 |
| CVE-2026-86097 | MEDIUM | 6.5 | PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_backup_file() functions that allows attackers to crash the autopilot process. Attackers can … | Sep 04, 2026 |
| CVE-2026-86096 | MEDIUM | 5.9 | PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race condition between task spawning and object deletion. Attackers can trigger the … | Sep 04, 2026 |
| CVE-2026-86095 | HIGH | 7.8 | Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers … | Sep 04, 2026 |
| CVE-2026-48019 | HIGH | 8.9 | Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony … | Sep 04, 2026 |
| CVE-2026-86091 | HIGH | 7.1 | ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers … | Sep 04, 2026 |
| CVE-2026-86090 | HIGH | 7.1 | ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to … | Sep 04, 2026 |
| CVE-2026-82684 | HIGH | 8.1 | Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or … | Sep 04, 2026 |
| CVE-2026-77393 | HIGH | 8.8 | In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute … | Sep 04, 2026 |
| CVE-2026-76925 | MEDIUM | 5.8 | A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. This vulnerability occurs because a privileged `chmod` … | Sep 04, 2026 |
| CVE-2026-75925 | CRITICAL | 9.6 | Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted … | Sep 04, 2026 |
| CVE-2026-46636 | UNKNOWN | — | Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. Twig\Markup … | Sep 04, 2026 |
| CVE-2026-85787 | MEDIUM | 6.5 | An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify … | Sep 04, 2026 |
| CVE-2026-85704 | LOW | 3.7 | A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file server/config.py of the component … | Sep 04, 2026 |
| CVE-2026-85703 | MEDIUM | 6.5 | A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/backend.py of the … | Sep 04, 2026 |
| CVE-2026-85702 | HIGH | 7.3 | A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file server/backend.py of the component Backend … | Sep 04, 2026 |
| CVE-2026-85701 | MEDIUM | 5.3 | A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the file g4f/__init__.py of the component Authentication … | Sep 04, 2026 |