Recent Vulnerabilities

Sources: amazon_linux archlinux azure_linux bitnami_vulndb capec capec_enrichment_dashboard certeu certfr circl_kev cisa_known_exploited cna_scorecard cnvd csaf_abb csaf_adstecindustrialitgmbh csaf_amd csaf_aumariestergmbhcokg csaf_baadem2mproductsgmbh csaf_beckhoffautomationgmbhcokg csaf_bendergmbhcokg csaf_bosch csaf_bsi csaf_bsi_aggregator csaf_bsi_cvd_white csaf_bsi_white csaf_bsi_wid_white csaf_carlogavazziautomation csaf_certbund csaf_certvde csaf_cisa csaf_cisa_it csaf_cisa_ot csaf_cisco csaf_claaskgaa csaf_codesysgmbh csaf_dell csaf_duraggmbh csaf_endresshauserag csaf_ericsson csaf_euchnergmbhcokg csaf_festosecokg csaf_frauschersensortechnikgmbh csaf_hancom csaf_harmaninternational csaf_helmholzgmbhcokg csaf_himapaulhildebrandtgmbh csaf_hitachi csaf_hpe csaf_huawei csaf_hydacinternationalgmbh csaf_ibm csaf_ifmelectronicgmbh csaf_janitzaelectronicsgmbh csaf_jumogmbhcokg csaf_juniper csaf_kebautomationkg csaf_kukaag csaf_lenovo csaf_lenzese csaf_mbconnectlinegmbh csaf_mettlertoledogmbh csaf_metzconnectgmbh csaf_microsoft csaf_mieleciekg csaf_moxa csaf_murrelektronikgmbh csaf_ncscnl csaf_ndaal csaf_netapp csaf_nozomi csaf_nozominetworks csaf_nvidia csaf_opcfoundation csaf_openeuler csaf_opensuse csaf_oracle csaf_ox csaf_paloalto csaf_panasonic csaf_pentagrid csaf_pepperlfuchsse csaf_phoenix csaf_pilzgmbhcokg csaf_qnap csaf_redhat csaf_samsung csaf_sauterag csaf_schneider csaf_sick csaf_siemens csaf_smasolartechnologyag csaf_suse csaf_swarcotrafficsystemsgmbh csaf_synology csaf_tibco csaf_trend csaf_trumpfsecokg csaf_trustsource csaf_tuxcare csaf_ubiquiti csaf_vartastoragegmbh csaf_vegagrieshaberkg csaf_vmware csaf_wagogmbhcokg csaf_weidmuellerinterfacegmbhcokg csaf_welotecgmbh csaf_wiesemanntheisgmbh csaf_yaskawaeuropegmbh csaf_yokogawa csaf_zyxel cve_forecast cve_icu cve_vs_github_dashboard cvelistv5 cwe_dashboard cwe_enrichment cwec debian_security_tracker drupal emb3d emb3d_dashboard epss_dashboard epss_history epss_kev_enrichment euvd_kev fedora fkie_nvd freebsd gcve gcve_enriched gcve_enrichment gcve_enrichment_dashboard gentoo github gsd jvn kev_ransomware mitre_attack moksha ndaal_kev netbsd nuclei_dashboard nuclei_enrichment nvd nvd_cpe_dictionary openbsd opencve oracle_linux ossf_malicious_packages osv_almalinux osv_alpine osv_bellsoft osv_chainguard osv_cran osv_github_actions osv_golang osv_haskell osv_hex osv_maven osv_npm osv_nuget osv_ocaml osv_ossfuzz osv_packagist osv_pub osv_rocky osv_rubygems osv_rustsec osv_swift osv_ubuntu osv_wolfi publish_stats pysec sadp_pilot ssvc ssvc_dashboard tailscale tsunami_enrichment variot vulnrichment Clear
ID Title Severity CVSS Source Updated
cve-2026-37603 Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0. The CAPTCHA escalation flag is stored in the PHP session as captcha_admin_enabled and the CAPTCHA form element is only built when that flag is present, so a remote unauthenticated attacker who obtains a new session before each login attempt is never presented with the challenge. MEDIUM 6.5 cvelistv5 2026-09-23
cve-2026-96807 In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_ld_cache to write files at an arbitrary location. The filenames and content are not attacker controlled, making this hard to exploit. MEDIUM 4.0 cvelistv5 2026-09-23
cve-2026-95847 Moquette client IDs can cause cross-session H2 durable-queue corruption HIGH 8.8 cvelistv5 2026-09-23
cve-2026-95842 Moquette uncaught MQTT command exceptions can terminate shared session event loops HIGH 8.7 cvelistv5 2026-09-23
cve-2026-96755 orval @orval/effect 8.14.0 through 8.28.1 Code Injection CRITICAL 9.3 cvelistv5 2026-09-23
cve-2026-86708 cve-2026-86708 CRITICAL 10.0 cvelistv5 unknown
cve-2026-86679 cve-2026-86679 HIGH 7.1 cvelistv5 unknown
cve-2026-76979 XML Injection vulnerability HIGH 7.7 cvelistv5 2026-09-23
cve-2026-76978 Command Injection vulnerability HIGH 8.8 cvelistv5 2026-09-23
cve-2026-75825 Authentication Bypass vulnerability HIGH 8.8 cvelistv5 2026-09-23
cve-2026-19599 Remote Code Execution vulnerability CRITICAL 9.9 cvelistv5 2026-09-23
cve-2026-96655 Plex Media Server arbitrary-host SSRF MEDIUM 4.3 cvelistv5 2026-09-23
cve-2026-96654 Plex Media Server URL injection MEDIUM 6.9 cvelistv5 2026-09-23
cve-2026-96652 Plex Media Server SSRF MEDIUM 4.3 cvelistv5 2026-09-23
cve-2026-96651 Plex Media Server path traversal MEDIUM 6.5 cvelistv5 2026-09-23
cve-2026-86677 cve-2026-86677 HIGH 8.8 cvelistv5 unknown
cve-2026-6669 Unbounded SCRAM iteration count causes CPU exhaustion in PgBouncer MEDIUM 5.9 cvelistv5 2026-09-23
cve-2026-6668 Integer overflow causes an infinite loop in packet buffer growth in PgBouncer HIGH 7.5 cvelistv5 2026-09-23
cve-2026-19888 NULL pointer dereference in SCRAM client-final-message parsing in PgBouncer HIGH 7.5 cvelistv5 2026-09-23
cve-2026-96656 Plex Media Server arbitrary file write HIGH 8.6 cvelistv5 2026-09-23
cve-2026-96514 Neethuharii CafeManagement Login CafePortalLogin.php sql injection MEDIUM 6.9 cvelistv5 2026-09-23
cve-2026-93769 HumHub 1.18.5 - Stored XSS in Profile Field Category title via HForm#renderForm leading to System Administrator account takeover HIGH 7.2 cvelistv5 2026-09-23
cve-2026-96804 CVE-2026-96804 UNKNOWN cvelistv5 2026-09-23
cve-2026-93349 Frictionless OS Command Injection via explore Console Command HIGH 8.6 cvelistv5 2026-09-23
cve-2026-6327 Multiple Vulnerabilities in IBM Concert Software MEDIUM 4.3 cvelistv5 2026-09-23
cve-2026-19087 IBM Financial Transaction Manager (FTM) is Impacted by Multiple Vulnerabilities MEDIUM 4.4 cvelistv5 2026-09-23
cve-2026-96513 Neethuharii CafeManagement AddProductCode.php unrestricted upload MEDIUM 6.9 cvelistv5 2026-09-23
cve-2026-95848 Moquette fails open when configured authentication or authorization classes cannot load CRITICAL 9.3 cvelistv5 2026-09-23
cve-2026-95846 Moquette publishes Last-Will messages without enforcing write authorization HIGH 8.7 cvelistv5 2026-09-23
cve-2026-95845 Moquette unbounded per-session message queues allow memory exhaustion HIGH 8.7 cvelistv5 2026-09-23