Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54499
Total
4309
Critical
16193
High
15930
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-84399 | HIGH | 8.8 | The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session … | Sep 24, 2026 |
| CVE-2026-82566 | HIGH | 8.8 | The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been … | Sep 24, 2026 |
| CVE-2026-82372 | UNKNOWN | — | Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in application … | Sep 24, 2026 |
| CVE-2026-82164 | HIGH | 7.1 | Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could … | Sep 24, 2026 |
| CVE-2026-77967 | HIGH | 8.1 | The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unauthenticated attacker … | Sep 24, 2026 |
| CVE-2026-48543 | MEDIUM | 5.4 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting … | Sep 24, 2026 |
| CVE-2026-48542 | MEDIUM | 5.4 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting … | Sep 24, 2026 |
| CVE-2026-48541 | MEDIUM | 5.4 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting … | Sep 24, 2026 |
| CVE-2026-48540 | MEDIUM | 5.4 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting … | Sep 24, 2026 |
| CVE-2026-97323 | MEDIUM | 6.3 | A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOriginalFilename of the file yudao-module-mp/src/main/java/cn/iocoder/yudao/module/mp/service/material/MpMaterialServiceImpl.java of the component File Upload. Executing … | Sep 24, 2026 |
| CVE-2026-97322 | MEDIUM | 4.3 | A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/file/FileController.java of the component File Upload. Performing … | Sep 24, 2026 |
| CVE-2026-97321 | MEDIUM | 6.3 | A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function GoViewDataServiceImpl.getDataBySQL of the file yudao-module-report/src/main/java/cn/iocoder/yudao/module/report/service/goview/GoViewDataServiceImpl.java of the component … | Sep 24, 2026 |
| CVE-2026-97320 | MEDIUM | 6.3 | A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowledgeDocumentServiceImpl.readUrl of the file AiKnowledgeDocumentServiceImpl.java of the component … | Sep 24, 2026 |
| CVE-2026-96749 | HIGH | 8.4 | An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built … | Sep 24, 2026 |
| CVE-2026-96748 | MEDIUM | 6.5 | PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a … | Sep 24, 2026 |
| CVE-2026-96747 | MEDIUM | 5.0 | The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix … | Sep 24, 2026 |
| CVE-2026-89325 | HIGH | 7.8 | An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as … | Sep 24, 2026 |
| CVE-2026-86860 | UNKNOWN | — | ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, … | Sep 24, 2026 |
| CVE-2026-86859 | UNKNOWN | — | ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unauthenticated … | Sep 24, 2026 |
| CVE-2026-86858 | UNKNOWN | — | ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated user, … | Sep 24, 2026 |
| CVE-2026-86857 | UNKNOWN | — | ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authenticated … | Sep 24, 2026 |
| CVE-2026-85738 | MEDIUM | 6.3 | TREK is a collaborative travel planner. Prior to 3.4.0, the checkSsrf logic in server/src/utils/ssrfGuard.ts does not recognize NAT64, 6to4, or Teredo IPv6 transition addresses that … | Sep 24, 2026 |
| CVE-2026-82371 | UNKNOWN | — | Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals with file read access to retrieve administrative switch credentials and … | Sep 24, 2026 |
| CVE-2026-82157 | HIGH | 8.3 | Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, … | Sep 24, 2026 |
| CVE-2026-81473 | HIGH | 8.1 | Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this … | Sep 24, 2026 |