Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54704
Total
4321
Critical
16261
High
15994
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-97368 | MEDIUM | 6.3 | A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInfo of the file blade-service/blade-system/src/main/java/org/springblade/system/service/impl/UserServiceImpl.java of the component user-auth-info Endpoint. … | Sep 24, 2026 |
| CVE-2026-97366 | MEDIUM | 6.3 | A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function openDevTools of the file electron/window.js of the … | Sep 24, 2026 |
| CVE-2026-95699 | CRITICAL | 9.6 | Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data … | Sep 24, 2026 |
| CVE-2026-93353 | MEDIUM | 5.3 | copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users to create, remove, and truncate arbitrary paths outside … | Sep 24, 2026 |
| CVE-2026-88388 | HIGH | 7.5 | Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace handling path on 64-bit builds. A remote attacker can supply … | Sep 24, 2026 |
| CVE-2026-88387 | UNKNOWN | — | LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF tag 0x00fe (NewSubfileType). A specially crafted RAW, TIFF, or DNG file can … | Sep 24, 2026 |
| CVE-2026-88386 | UNKNOWN | — | libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A specially crafted WAV file can cause the function to … | Sep 24, 2026 |
| CVE-2026-87118 | MEDIUM | 5.7 | The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality. An authenticated attacker with adjacent network access … | Sep 24, 2026 |
| CVE-2026-84403 | MEDIUM | 6.2 | The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. … | Sep 24, 2026 |
| CVE-2026-82716 | MEDIUM | 4.6 | The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process. These logs remain accessible … | Sep 24, 2026 |
| CVE-2026-82708 | MEDIUM | 6.5 | The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could … | Sep 24, 2026 |
| CVE-2026-82585 | MEDIUM | 6.5 | The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi … | Sep 24, 2026 |
| CVE-2026-81630 | HIGH | 8.1 | The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and … | Sep 24, 2026 |
| CVE-2026-79959 | MEDIUM | 6.8 | The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware … | Sep 24, 2026 |
| CVE-2026-75558 | MEDIUM | 5.3 | The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who … | Sep 24, 2026 |
| CVE-2026-14443 | UNKNOWN | — | Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system logs. … | Sep 24, 2026 |
| CVE-2026-14442 | UNKNOWN | — | An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be written to application logs in plain text. When scheduled … | Sep 24, 2026 |
| CVE-2026-14441 | UNKNOWN | — | A logic flaw in Java cache key handling object comparison handling could lead to improper identifier resolution when processing specific user account structures. The issue … | Sep 24, 2026 |
| CVE-2026-97365 | MEDIUM | 6.3 | A vulnerability was determined in chonkie-inc littrs 0.6.1/0.6.2. Impacted is the function Sandbox::mount of the file crates/littrs/src/lib.rs. Executing a manipulation of the argument relative can … | Sep 24, 2026 |
| CVE-2026-97326 | HIGH | 7.3 | A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this issue is some unknown functionality of the file chat-server/src/main/java/cn/sinjinsong/chat/server/ChatServer.java of the … | Sep 24, 2026 |
| CVE-2026-97325 | MEDIUM | 4.3 | A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability is the function validOAuthClientFromCache of the file yudao-module-system/src/main/java/cn/iocoder/yudao/module/system/service/oauth2/OAuth2ClientServiceImpl.java of … | Sep 24, 2026 |
| CVE-2026-97324 | HIGH | 7.3 | A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderController.java of the component Demo-order Payment Callback … | Sep 24, 2026 |
| CVE-2026-96883 | HIGH | 8.8 | pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to … | Sep 24, 2026 |
| CVE-2026-93354 | HIGH | 8.1 | Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting … | Sep 24, 2026 |
| CVE-2026-93291 | CRITICAL | 9.4 | Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code. | Sep 24, 2026 |