Recent Vulnerabilities

Sources: amazon_linux archlinux azure_linux bitnami_vulndb capec capec_enrichment_dashboard certeu certfr circl_kev cisa_known_exploited cna_scorecard cnvd csaf_abb csaf_adstecindustrialitgmbh csaf_amd csaf_aumariestergmbhcokg csaf_baadem2mproductsgmbh csaf_beckhoffautomationgmbhcokg csaf_bendergmbhcokg csaf_bosch csaf_bsi csaf_bsi_aggregator csaf_bsi_cvd_white csaf_bsi_white csaf_bsi_wid_white csaf_carlogavazziautomation csaf_certbund csaf_certvde csaf_cisa csaf_cisa_it csaf_cisa_ot csaf_cisco csaf_claaskgaa csaf_codesysgmbh csaf_dell csaf_duraggmbh csaf_endresshauserag csaf_ericsson csaf_euchnergmbhcokg csaf_festosecokg csaf_frauschersensortechnikgmbh csaf_hancom csaf_harmaninternational csaf_helmholzgmbhcokg csaf_himapaulhildebrandtgmbh csaf_hitachi csaf_hpe csaf_huawei csaf_hydacinternationalgmbh csaf_ibm csaf_ifmelectronicgmbh csaf_janitzaelectronicsgmbh csaf_jumogmbhcokg csaf_juniper csaf_kebautomationkg csaf_kukaag csaf_lenovo csaf_lenzese csaf_mbconnectlinegmbh csaf_mettlertoledogmbh csaf_metzconnectgmbh csaf_microsoft csaf_mieleciekg csaf_moxa csaf_murrelektronikgmbh csaf_ncscnl csaf_ndaal csaf_netapp csaf_nozomi csaf_nozominetworks csaf_nvidia csaf_opcfoundation csaf_openeuler csaf_opensuse csaf_oracle csaf_ox csaf_paloalto csaf_panasonic csaf_pentagrid csaf_pepperlfuchsse csaf_phoenix csaf_pilzgmbhcokg csaf_qnap csaf_redhat csaf_samsung csaf_sauterag csaf_schneider csaf_sick csaf_siemens csaf_smasolartechnologyag csaf_suse csaf_swarcotrafficsystemsgmbh csaf_synology csaf_tibco csaf_trend csaf_trumpfsecokg csaf_trustsource csaf_tuxcare csaf_ubiquiti csaf_vartastoragegmbh csaf_vegagrieshaberkg csaf_vmware csaf_wagogmbhcokg csaf_weidmuellerinterfacegmbhcokg csaf_welotecgmbh csaf_wiesemanntheisgmbh csaf_yaskawaeuropegmbh csaf_yokogawa csaf_zyxel cve_forecast cve_icu cve_vs_github_dashboard cvelistv5 cwe_dashboard cwe_enrichment cwec debian_security_tracker drupal emb3d emb3d_dashboard epss_dashboard epss_history epss_kev_enrichment euvd_kev fedora fkie_nvd freebsd gcve gcve_enriched gcve_enrichment gcve_enrichment_dashboard gentoo github gsd jvn kev_ransomware mitre_attack moksha ndaal_kev netbsd nuclei_dashboard nuclei_enrichment nvd nvd_cpe_dictionary openbsd opencve oracle_linux ossf_malicious_packages osv_almalinux osv_alpine osv_bellsoft osv_chainguard osv_cran osv_github_actions osv_golang osv_haskell osv_hex osv_maven osv_npm osv_nuget osv_ocaml osv_ossfuzz osv_packagist osv_pub osv_rocky osv_rubygems osv_rustsec osv_swift osv_ubuntu osv_wolfi publish_stats pysec sadp_pilot ssvc ssvc_dashboard tailscale tsunami_enrichment variot vulnrichment
ID Title Severity CVSS Source Updated
cve-2026-94127 EUVD-2026-84427 CRITICAL 9.8 cvelistv5 Sep 23, 2026, 3:55:44 AM
cve-2026-93616 EUVD-2026-84375 CRITICAL 9.8 cvelistv5 Sep 23, 2026, 3:55:59 AM
cve-2026-93952 EUVD-2026-84296 CRITICAL 10.0 cvelistv5 Sep 23, 2026, 3:55:40 AM
cve-2026-85102 EUVD-2026-75009 CRITICAL 9.8 cvelistv5 Sep 23, 2026, 3:55:34 AM
cve-2026-54648 CubeCart: Missing Authorization Check in customers.gdpr.inc.php Leads to Unauthorized Customer Data Deletion MEDIUM 6.5 cvelistv5 2026-09-23
cve-2026-54647 CubeCart : SQL Injection via download_expire Parameter in settings.index.inc.php HIGH 7.2 cvelistv5 2026-09-23
cve-2026-54646 CubeCart: SQL Identifier Injection via Backtick Bypass in maintenance.index.inc.php HIGH 7.2 cvelistv5 2026-09-23
cve-2026-54643 CubeCart: Missing Authorization Check for Order Note Deletion in orders.index.inc.php MEDIUM 5.4 cvelistv5 2026-09-23
cve-2026-54642 CubeCart: CSRF Protection Missing for Download Resets and Card Deletions in orders.index.inc.php MEDIUM 5.3 cvelistv5 2026-09-23
cve-2026-54608 MythicalDash: Unauthenticated payment bypass in Stripe success-redirect endpoint allows arbitrary free credit top-up HIGH 7.1 cvelistv5 2026-09-23
cve-2026-28663 In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. HIGH 7.8 cvelistv5 2026-09-23
cve-2026-19202 Token Cache Reuse in mcp-toolbox-sdk-python CRITICAL 9.1 cvelistv5 2026-09-23
cve-2026-28664 In WriteImageToDisk of runtime_image.cc, there is a possible file tampering due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. HIGH 7.8 cvelistv5 2026-09-23
cve-2026-19888 NULL pointer dereference in SCRAM client-final-message parsing in PgBouncer HIGH 7.5 cvelistv5 2026-09-23
cve-2026-28666 In multiple functions of LocalImageResolver.java, there is a possible Remote Persistent Denial of Service due to a DNG image rendering check bypass. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. HIGH 8.8 cvelistv5 2026-09-23
cve-2026-28668 In LimitRealloc of malloc_limit.cpp, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. HIGH 7.8 cvelistv5 2026-09-23
cve-2026-28671 In updateInternal of MediaProvider.java, there is a possible expose contents of files due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. LOW 3.3 cvelistv5 2026-09-23
cve-2026-45531 In read_boot_region of fsck.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. HIGH 7.8 cvelistv5 2026-09-23
cve-2026-49879 In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. HIGH 8.8 cvelistv5 2026-09-23
cve-2026-49881 In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. HIGH 7.8 cvelistv5 2026-09-23
cve-2026-49882 In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. HIGH 8.8 cvelistv5 2026-09-23
cve-2026-49884 In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. HIGH 7.8 cvelistv5 2026-09-23
mal-2026-16475 Malicious code in memoryos (PyPI) UNKNOWN ossf_malicious_packages unknown
cve-2026-63132 OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack CRITICAL 9.2 cvelistv5 2026-09-23
cve-2026-63131 OpenBao LIST ACL bypass: a trailing-slash LIST request skips a more-specific deny rule (unported Vault v2.0.3 fix) MEDIUM 6.0 cvelistv5 2026-09-23
cve-2026-61814 Jawn: Quadratic parsing effort in AsyncParser HIGH 7.5 cvelistv5 2026-09-23
cve-2026-61695 Wire Swift runtime: negative LENGTH_DELIMITED length in skipGroup() crashes any protobuf-decoding service HIGH 7.5 cvelistv5 2026-09-23
cve-2026-59990 Jawn: Uncontrolled nesting depth in JSON parser HIGH 7.5 cvelistv5 2026-09-23
cve-2026-55632 GoCD is vulnerable to authorization bypass via pipeline structure API MEDIUM 4.3 cvelistv5 2026-09-23
cve-2026-55456 Rejected reason: This CVE is a duplicate of another CVE. UNKNOWN cvelistv5 2026-09-23