NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-61629 nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server... 2026-09-21 7.5 NETWORK HIGH NVD
CVE-2026-61628 nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (... 2026-09-21 8.1 NETWORK HIGH NVD
CVE-2026-55870 GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators stored in the userinfo portion of sourc... 2026-09-21 2.3 NETWORK LOW NVD
CVE-2026-55625 GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/admin/internal/material_test and ... 2026-09-21 4.9 NETWORK MEDIUM NVD
CVE-2026-55567 BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's p... 2026-09-21 7.8 LOCAL HIGH NVD
CVE-2026-55071 MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0, the ado_package_install MCP ... 2026-09-21 8.4 LOCAL HIGH NVD
CVE-2026-55060 GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-o... 2026-09-21 3.7 NETWORK LOW NVD
CVE-2026-52743 GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ... 2026-09-21 4.3 NETWORK MEDIUM NVD
CVE-2026-52742 GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server configuration to ... 2026-09-21 5.1 NETWORK MEDIUM NVD
CVE-2026-52741 GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from commit comments when a project use... 2026-09-21 7.5 NETWORK HIGH NVD
CVE-2026-52740 GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names case-sensitively when selecting ... 2026-09-21 5.3 NETWORK MEDIUM NVD
CVE-2026-88807 A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients. 2026-09-21 8.9 NETWORK HIGH NVD
CVE-2026-88806 A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map. 2026-09-21 7.5 NETWORK HIGH NVD
CVE-2026-94368 A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway. The issue occurs when... 2026-09-21 7.1 NETWORK HIGH NVD
CVE-2026-91867 When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can ke... 2026-09-21 4.3 NETWORK MEDIUM NVD