Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42183
Total
3433
Critical
12465
High
12416
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-84199 | HIGH | 7.7 | Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, … | Sep 01, 2026 |
| CVE-2026-84196 | HIGH | 7.7 | Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecting user-controlled input through … | Sep 01, 2026 |
| CVE-2026-84195 | HIGH | 7.7 | Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate … | Sep 01, 2026 |
| CVE-2026-84194 | UNKNOWN | — | LibreNMS versions >= 23.10.0 and < 26.2.0 (fixed in 26.4.0) contain an authenticated OS command injection vulnerability in libvirt discovery. When libvirt support is enabled … | Sep 01, 2026 |
| CVE-2026-84193 | UNKNOWN | — | LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer descriptions, VRF … | Sep 01, 2026 |
| CVE-2026-84192 | HIGH | 7.1 | LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without escaping. An attacker who controls … | Sep 01, 2026 |
| CVE-2026-84191 | MEDIUM | 6.1 | LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages where mplsVpnVrfDescription, vrf_name, and mplsVpnVrfRouteDistinguisher fields from SNMP polling are rendered without sanitization. … | Sep 01, 2026 |
| CVE-2026-84190 | HIGH | 7.2 | LibreNMS versions before 26.5.0 contain a remote code execution vulnerability in the AboutController where the snmpget configuration parameter is passed to shell_exec() without proper validation. … | Sep 01, 2026 |
| CVE-2026-84189 | HIGH | 8.1 | LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the device showconfig page … | Sep 01, 2026 |
| CVE-2026-84188 | MEDIUM | 4.8 | LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.<graphtype> configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php. An … | Sep 01, 2026 |
| CVE-2026-84187 | HIGH | 8.2 | AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticated attackers to mark arbitrary scheduled broadcasts as failed by sending crafted POST requests with … | Sep 01, 2026 |
| CVE-2026-83595 | HIGH | 8.1 | AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform state-changing actions by crafting GET requests that bypass CSRF protection. Attackers … | Sep 01, 2026 |
| CVE-2026-77194 | MEDIUM | 5.3 | The Simple Membership plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in versions up to, and including, 4.8.0. This is … | Sep 01, 2026 |
| CVE-2026-76111 | HIGH | 8.8 | Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege … | Sep 01, 2026 |
| CVE-2026-18550 | CRITICAL | 9.8 | The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. … | Sep 01, 2026 |
| CVE-2026-11873 | MEDIUM | 6.5 | An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same … | Sep 01, 2026 |
| CVE-2026-10420 | MEDIUM | 5.5 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be. | Sep 01, 2026 |
| CVE-2025-15613 | MEDIUM | 6.5 | Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attacker with permission to create Kyverno (Cluster)Policies can specify … | Sep 01, 2026 |
| CVE-2023-54356 | LOW | 3.7 | Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These 64-bit block ciphers are vulnerable to the … | Sep 01, 2026 |
| CVE-2026-84165 | UNKNOWN | — | A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user … | Sep 01, 2026 |
| CVE-2026-84059 | HIGH | 7.4 | A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 20260704. The affected element is the function ArmAngstromInstructionSet of the file /CGI?RestApi=SetHostname. … | Sep 01, 2026 |
| CVE-2026-82927 | MEDIUM | 5.5 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e. | Sep 01, 2026 |
| CVE-2026-82926 | MEDIUM | 5.5 | NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a. | Sep 01, 2026 |
| CVE-2026-4813 | UNKNOWN | — | A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticated administrators to execute code remotely. The XML/XSLT processing … | Sep 01, 2026 |
| CVE-2026-59681 | HIGH | 8.8 | A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory configuration values to execute arbitrary commands as root on the configured … | Sep 01, 2026 |