NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-96260 Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF va... 2026-09-22 6.5 NETWORK MEDIUM NVD
CVE-2026-96259 Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal-connection filter to OAuth en... 2026-09-22 5.5 NETWORK MEDIUM NVD
CVE-2026-95814 Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-... 2026-09-22 8.1 NETWORK HIGH NVD
CVE-2026-94450 Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial ... 2026-09-22 7.5 NETWORK HIGH NVD
CVE-2026-91018 lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the vi... 2026-09-22 8.8 ADJACENT_NETWORK HIGH NVD
CVE-2026-88020 Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempt... 2026-09-22 6.1 NETWORK MEDIUM NVD
CVE-2026-77987 A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated th... 2026-09-22 9.3 NETWORK CRITICAL NVD
CVE-2026-77912 A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrar... 2026-09-22 7.4 NETWORK HIGH NVD
CVE-2026-77426 Unleash is an open-source feature management platform. Prior to 8.0.3, the Unleash admin API contains five authorization vulnerabilities. POST /api/ad... 2026-09-22 7.1 NETWORK HIGH NVD
CVE-2026-77425 Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:featureName/environments/:environ... 2026-09-22 4.3 NETWORK MEDIUM NVD
CVE-2026-76910 Unleash is an open-source feature management platform. Prior to 8.0.3, cloneFeatureToggle and POST /api/admin/projects/:projectId/features/:featureNam... 2026-09-22 5.3 NETWORK MEDIUM NVD
CVE-2026-76909 Unleash is an open-source feature management platform. Prior to 8.0.3, the change-request approval email template at src/mailtemplates/requested-cr-ap... 2026-09-22 2.1 NETWORK LOW NVD
CVE-2026-75101 An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw d... 2026-09-22 6.0 NETWORK MEDIUM NVD
CVE-2026-67615 openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability that allows any authenticated non-guest user to execute arbi... 2026-09-22 8.8 NETWORK HIGH NVD
CVE-2026-62364 wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration from .weblate, .weblate.ini, or ... 2026-09-22 2.3 LOCAL LOW NVD