Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54499
Total
4309
Critical
16193
High
15930
Medium
CVE ID Severity Score Description Published
CVE-2026-84399 HIGH 8.8 The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session … Sep 24, 2026
CVE-2026-82566 HIGH 8.8 The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been … Sep 24, 2026
CVE-2026-82372 UNKNOWN — Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in application … Sep 24, 2026
CVE-2026-82164 HIGH 7.1 Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could … Sep 24, 2026
CVE-2026-77967 HIGH 8.1 The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unauthenticated attacker … Sep 24, 2026
CVE-2026-48543 MEDIUM 5.4 Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting … Sep 24, 2026
CVE-2026-48542 MEDIUM 5.4 Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting … Sep 24, 2026
CVE-2026-48541 MEDIUM 5.4 Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting … Sep 24, 2026
CVE-2026-48540 MEDIUM 5.4 Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting … Sep 24, 2026
CVE-2026-97323 MEDIUM 6.3 A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOriginalFilename of the file yudao-module-mp/src/main/java/cn/iocoder/yudao/module/mp/service/material/MpMaterialServiceImpl.java of the component File Upload. Executing … Sep 24, 2026
CVE-2026-97322 MEDIUM 4.3 A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/file/FileController.java of the component File Upload. Performing … Sep 24, 2026
CVE-2026-97321 MEDIUM 6.3 A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function GoViewDataServiceImpl.getDataBySQL of the file yudao-module-report/src/main/java/cn/iocoder/yudao/module/report/service/goview/GoViewDataServiceImpl.java of the component … Sep 24, 2026
CVE-2026-97320 MEDIUM 6.3 A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowledgeDocumentServiceImpl.readUrl of the file AiKnowledgeDocumentServiceImpl.java of the component … Sep 24, 2026
CVE-2026-96749 HIGH 8.4 An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built … Sep 24, 2026
CVE-2026-96748 MEDIUM 6.5 PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a … Sep 24, 2026
CVE-2026-96747 MEDIUM 5.0 The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix … Sep 24, 2026
CVE-2026-89325 HIGH 7.8 An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as … Sep 24, 2026
CVE-2026-86860 UNKNOWN — ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, … Sep 24, 2026
CVE-2026-86859 UNKNOWN — ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unauthenticated … Sep 24, 2026
CVE-2026-86858 UNKNOWN — ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated user, … Sep 24, 2026
CVE-2026-86857 UNKNOWN — ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authenticated … Sep 24, 2026
CVE-2026-85738 MEDIUM 6.3 TREK is a collaborative travel planner. Prior to 3.4.0, the checkSsrf logic in server/src/utils/ssrfGuard.ts does not recognize NAT64, 6to4, or Teredo IPv6 transition addresses that … Sep 24, 2026
CVE-2026-82371 UNKNOWN — Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals with file read access to retrieve administrative switch credentials and … Sep 24, 2026
CVE-2026-82157 HIGH 8.3 Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, … Sep 24, 2026
CVE-2026-81473 HIGH 8.1 Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this … Sep 24, 2026