Common Vulnerabilities and Exposures (CVE)

CVE-2026-73597

Sep 29, 2026 11:57:10 UTC

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading...

CVE-2026-101266

Sep 29, 2026 11:53:52 UTC

A logic flaw in the checkout flow allows users to bypass validations performed during the check-in by skipping entire check-in steps.

CVE-2026-73596

Sep 29, 2026 11:52:26 UTC

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A high privileged attacker with remote access could potentially exploit this vu...

CVE-2026-87748

Sep 29, 2026 11:51:55 UTC

Missing Authorization vulnerability in Interprobe Information Technologies Inc. Qorela DC allows Privilege Abuse. This issue affects Qorela DC: from 1.6.1-RC29 before v1.6.2.

CVE-2026-102507

Sep 29, 2026 11:49:54 UTC

Sliver C2 framework version 1.7.7 and earlier contains an unhandled panic vulnerability in the operator gRPC handler that allows an attacker controlling a compromised implant to crash the entire teamserver by returning a malformed or empty ...

CVE-2026-66083

Sep 29, 2026 11:46:40 UTC

The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. This may expose data...

CVE-2026-41875

Sep 29, 2026 11:43:40 UTC

Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request that changes admin's login and password. Thi...

CVE-2026-73595

Sep 29, 2026 11:39:50 UTC

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potentially expl...

CVE-2026-85520

Sep 29, 2026 11:39:09 UTC

Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the feed.php endpoint. An unauthenticated attacker can send a crafted request that controls the output file name, path, exte...

CVE-2026-102497

Sep 29, 2026 11:34:17 UTC

The Apache XmlSchema walker (xmlschema-walker) doesn't detect cycles in type derivation, substitution groups, model groups or attribute groups. A malicious schema with such a cycle can make the walker recurse until the stack overflows, caus...

CVE-2026-102496

Sep 29, 2026 11:34:04 UTC

Apache XmlSchema doesn't limit how deeply schema structures can be nested when it builds its schema model, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to u...

CVE-2026-102495

Sep 29, 2026 11:33:51 UTC

Apache XmlSchema doesn't limit how deeply schema imports and includes can be nested, so a malicious schema can make parsing recurse until the stack overflows. This causes a denial of service. Users are recommended to upgrade to version 2.3....

CVE-2026-73594

Sep 29, 2026 11:32:10 UTC

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially ex...

CVE-2026-73593

Sep 29, 2026 11:26:58 UTC

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Active Debug Code vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information d...

CVE-2026-10832

Sep 29, 2026 11:20:14 UTC

A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability by sending a specially crafted DER (Distinguished Encoding Rules) payload. The decoder attempts to al...