Recent Vulnerabilities

Sources: amazon_linux archlinux azure_linux bitnami_vulndb capec capec_enrichment_dashboard certeu certfr circl_kev cisa_known_exploited cna_scorecard cnvd csaf_abb csaf_adstecindustrialitgmbh csaf_amd csaf_aumariestergmbhcokg csaf_baadem2mproductsgmbh csaf_beckhoffautomationgmbhcokg csaf_bendergmbhcokg csaf_bosch csaf_bsi csaf_bsi_aggregator csaf_bsi_cvd_white csaf_bsi_white csaf_bsi_wid_white csaf_carlogavazziautomation csaf_certbund csaf_certvde csaf_cisa csaf_cisa_it csaf_cisa_ot csaf_cisco csaf_claaskgaa csaf_codesysgmbh csaf_dell csaf_duraggmbh csaf_endresshauserag csaf_ericsson csaf_euchnergmbhcokg csaf_festosecokg csaf_frauschersensortechnikgmbh csaf_hancom csaf_harmaninternational csaf_helmholzgmbhcokg csaf_himapaulhildebrandtgmbh csaf_hitachi csaf_hpe csaf_huawei csaf_hydacinternationalgmbh csaf_ibm csaf_ifmelectronicgmbh csaf_janitzaelectronicsgmbh csaf_jumogmbhcokg csaf_juniper csaf_kebautomationkg csaf_kukaag csaf_lenovo csaf_lenzese csaf_mbconnectlinegmbh csaf_mettlertoledogmbh csaf_metzconnectgmbh csaf_microsoft csaf_mieleciekg csaf_moxa csaf_murrelektronikgmbh csaf_ncscnl csaf_ndaal csaf_netapp csaf_nozomi csaf_nozominetworks csaf_nvidia csaf_opcfoundation csaf_openeuler csaf_opensuse csaf_oracle csaf_ox csaf_paloalto csaf_panasonic csaf_pentagrid csaf_pepperlfuchsse csaf_phoenix csaf_pilzgmbhcokg csaf_qnap csaf_redhat csaf_samsung csaf_sauterag csaf_schneider csaf_sick csaf_siemens csaf_smasolartechnologyag csaf_suse csaf_swarcotrafficsystemsgmbh csaf_synology csaf_tibco csaf_trend csaf_trumpfsecokg csaf_trustsource csaf_tuxcare csaf_ubiquiti csaf_vartastoragegmbh csaf_vegagrieshaberkg csaf_vmware csaf_wagogmbhcokg csaf_weidmuellerinterfacegmbhcokg csaf_welotecgmbh csaf_wiesemanntheisgmbh csaf_yaskawaeuropegmbh csaf_yokogawa csaf_zyxel cve_forecast cve_icu cve_vs_github_dashboard cvelistv5 cwe_dashboard cwe_enrichment cwec debian_security_tracker drupal emb3d emb3d_dashboard epss_dashboard epss_history epss_kev_enrichment euvd_kev fedora fkie_nvd freebsd gcve gcve_enriched gcve_enrichment gcve_enrichment_dashboard gentoo github gsd jvn kev_ransomware mitre_attack moksha ndaal_kev netbsd nuclei_dashboard nuclei_enrichment nvd nvd_cpe_dictionary openbsd opencve oracle_linux ossf_malicious_packages osv_almalinux osv_alpine osv_bellsoft osv_chainguard osv_cran osv_github_actions osv_golang osv_haskell osv_hex osv_maven osv_npm osv_nuget osv_ocaml osv_ossfuzz osv_packagist osv_pub osv_rocky osv_rubygems osv_rustsec osv_swift osv_ubuntu osv_wolfi publish_stats pysec sadp_pilot ssvc ssvc_dashboard tailscale tsunami_enrichment variot vulnrichment Clear
ID Title Severity CVSS Source Updated
cve-2025-5278 SUSE CVE CVE-2025-5278 MEDIUM 4.4 cvelistv5 2026-08-31
cve-2026-14645 Nexus Repository 3 - Server-Side Request Forgery (SSRF) via Webhook: Global Capability MEDIUM 5.5 cvelistv5 2026-09-22
cve-2026-14646 Nexus Repository 3 - Server-Side Request Forgery (SSRF) via HTTP Redirect HIGH 7.7 cvelistv5 2026-09-22
cve-2026-10748 Nexus Repository 3 - Remote Code Execution via License Deserialization HIGH 7.2 cvelistv5 2026-09-22
cve-2026-55748 OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. MEDIUM 6.0 cvelistv5 2026-09-22
cve-2026-41862 Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM. Affected versions: Spring Statemachine 4.0.0 through 4.0.1 Spring Statemachine 3.2.0 through 3.2.4 HIGH 8.8 cvelistv5 2026-09-22
cve-2026-58381 Gimp: gimp: double-free in read_layer_block() MEDIUM 6.1 cvelistv5 2026-09-22
cve-2026-24220 NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A successful exploit of this vulnerability might lead to code execution. MEDIUM 6.4 cvelistv5 2026-09-22
cve-2026-56211 SUSE CVE CVE-2026-56211 HIGH 7.5 cvelistv5 2026-09-10
cve-2026-56210 Libaom: libaom: heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id HIGH 7.1 cvelistv5 2026-09-24
cve-2026-56209 SUSE CVE CVE-2026-56209 HIGH 8.1 cvelistv5 2026-08-30
cve-2026-56208 SUSE CVE CVE-2026-56208 HIGH 7.1 cvelistv5 2026-09-10
cve-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability HIGH cvelistv5 2026-09-21
cve-2026-7891 Rejected reason: This CVE has been retracted. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute. UNKNOWN cvelistv5 2026-09-22
cve-2025-48044 Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from ... HIGH 8.6 cvelistv5 2026-09-22
cve-2025-48043 Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from ... HIGH 8.6 cvelistv5 2026-09-22
cve-2025-4754 Missing Session Revocation on Logout in ash_authentication_phoenix LOW 2.3 cvelistv5 2026-09-22
cve-2025-48042 Incorrect Authorization vulnerability in ash-project ash allows Exploiting Incorrectly Configured Access Control Secu... HIGH 7.1 cvelistv5 2026-09-22
cve-2023-4548 A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3 LOW 2.1 cvelistv5 2026-09-22
cve-2023-4547 SPA-Cart eCommerce CMS search cross site scripting LOW 3.5 cvelistv5 2026-09-22
cve-2026-15711 Libsoup: soupwebsocketconnection: libsoup: websocket remote denial of service via oversized control frame protocol violation HIGH 7.5 cvelistv5 2026-09-24
cve-2026-15709 Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of service HIGH 7.5 cvelistv5 2026-09-24
cve-2023-6927 keycloak: open redirect via "form_post.jwt" JARM response mode MEDIUM 4.6 cvelistv5 2026-08-08
cve-2023-6563 keycloak: offline session token DoS HIGH 7.7 cvelistv5 2026-08-04
cve-2023-6291 keycloak: redirect_uri validation bypass HIGH 7.1 cvelistv5 2025-11-21
cve-2023-6134 keycloak: reflected XSS via wildcard in OIDC redirect_uri MEDIUM 4.6 cvelistv5 2026-08-04
cve-2026-15028 SUSE CVE CVE-2026-15028 UNKNOWN cvelistv5 2026-09-19
cve-2024-53920 SUSE CVE CVE-2024-53920 HIGH 7.8 cvelistv5 2026-09-13
cve-2024-40766 SonicWall SonicOS Improper Access Control Vulnerability CRITICAL cvelistv5 2024-09-09
cve-2026-5883 SUSE CVE CVE-2026-5883 HIGH 8.8 cvelistv5 2026-09-02