Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54704
Total
4321
Critical
16261
High
15994
Medium
CVE ID Severity Score Description Published
CVE-2026-93290 MEDIUM 5.5 Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data. Sep 24, 2026
CVE-2026-93289 HIGH 7.5 The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process. Sep 24, 2026
CVE-2026-88956 MEDIUM 6.8 The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface. The affected account does not … Sep 24, 2026
CVE-2026-88761 MEDIUM 5.3 The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product. An unauthenticated … Sep 24, 2026
CVE-2026-85496 HIGH 8.8 The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with … Sep 24, 2026
CVE-2026-84399 HIGH 8.8 The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session … Sep 24, 2026
CVE-2026-82566 HIGH 8.8 The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been … Sep 24, 2026
CVE-2026-82372 UNKNOWN — Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in application … Sep 24, 2026
CVE-2026-82164 HIGH 7.1 Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could … Sep 24, 2026
CVE-2026-77967 HIGH 8.1 The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unauthenticated attacker … Sep 24, 2026
CVE-2026-48543 MEDIUM 5.4 Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting … Sep 24, 2026
CVE-2026-48542 MEDIUM 5.4 Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting … Sep 24, 2026
CVE-2026-48541 MEDIUM 5.4 Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting … Sep 24, 2026
CVE-2026-48540 MEDIUM 5.4 Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting … Sep 24, 2026
CVE-2026-97323 MEDIUM 6.3 A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOriginalFilename of the file yudao-module-mp/src/main/java/cn/iocoder/yudao/module/mp/service/material/MpMaterialServiceImpl.java of the component File Upload. Executing … Sep 24, 2026
CVE-2026-97322 MEDIUM 4.3 A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/file/FileController.java of the component File Upload. Performing … Sep 24, 2026
CVE-2026-97321 MEDIUM 6.3 A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function GoViewDataServiceImpl.getDataBySQL of the file yudao-module-report/src/main/java/cn/iocoder/yudao/module/report/service/goview/GoViewDataServiceImpl.java of the component … Sep 24, 2026
CVE-2026-97320 MEDIUM 6.3 A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowledgeDocumentServiceImpl.readUrl of the file AiKnowledgeDocumentServiceImpl.java of the component … Sep 24, 2026
CVE-2026-96749 HIGH 8.4 An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built … Sep 24, 2026
CVE-2026-96748 MEDIUM 6.5 PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a … Sep 24, 2026
CVE-2026-96747 MEDIUM 5.0 The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix … Sep 24, 2026
CVE-2026-89325 HIGH 7.8 An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as … Sep 24, 2026
CVE-2026-86860 UNKNOWN — ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, … Sep 24, 2026
CVE-2026-86859 UNKNOWN — ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unauthenticated … Sep 24, 2026
CVE-2026-86858 UNKNOWN — ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated user, … Sep 24, 2026