Common Vulnerabilities and Exposures (CVE)

CVE-2025-40551

Oct 7, 2026 17:55:29 UTC

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited wit...

CVE-2026-15894

Oct 7, 2026 17:55:22 UTC

The Bluetooth Mesh On-Demand Private Proxy solicitation handler in subsys/bluetooth/mesh/solicitation.c copies a received Solicitation PDU into a fixed 17-byte stack buffer without bounding the source length. In sol_pdu_decrypt(), out is al...

CVE-2026-106511

Oct 7, 2026 17:55:09 UTC

MultiversX's multisig-improved (repository: mx-multisig-and-modules) reference implementation of their on-chain multisig smart contract system contains a vulnerability where a missing independent authorization check allows any account with ...

CVE-2025-3928

Oct 7, 2026 17:54:32 UTC

Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed...

CVE-2021-0158

Oct 7, 2026 17:54:13 UTC

Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2021-0157

Oct 7, 2026 17:52:59 UTC

Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2026-92393

Oct 7, 2026 17:52:46 UTC

Apache YuniKorn 1.9.0 and earlier does not implement label and user annotation checks for workload UPDATE action bypassing all checks. Workloads in YuniKorn are defined as the following Kubernetes objects: "deployments", "replicasets", "sta...

CVE-2026-106491

Oct 7, 2026 17:52:11 UTC

Backstage is an open framework for building developer portals. Prior to 0.6.17, the @backstage/plugin-proxy-backend package is affected by improper input validation in proxy-backend. An authenticated Backstage user could craft a request URL...

CVE-2025-21043

Oct 7, 2026 17:51:40 UTC

Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

CVE-2026-107216

Oct 7, 2026 17:51:31 UTC

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, ANCHORARRAY recursively calls the exported CalcCellValue function, creating a fresh calculation context at each cycle and bypassin...

CVE-2022-0235

Oct 7, 2026 17:51:24 UTC

node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

CVE-2025-21042

Oct 7, 2026 17:51:19 UTC

Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.

CVE-2026-78243

Oct 7, 2026 17:50:51 UTC

Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entries.If the LDAP server returns a group membership entry, memberOf attribute, for a user specif...

CVE-2026-95606

Oct 7, 2026 17:49:58 UTC

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Events Calendar allows Object Injection. This issue affects The Events Calendar: from n/a through 6.17.4.

CVE-2024-50623

Oct 7, 2026 17:49:17 UTC

In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.