Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54155
Total
4297
Critical
16098
High
15777
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-104474 | MEDIUM | 6.7 | OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the … | Oct 03, 2026 |
| CVE-2026-104433 | HIGH | 7.5 | Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by … | Oct 03, 2026 |
| CVE-2026-84411 | CRITICAL | 9.8 | The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can … | Oct 02, 2026 |
| CVE-2026-105051 | LOW | 1.9 | Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel). | Oct 02, 2026 |
| CVE-2026-105050 | UNKNOWN | — | PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in … | Oct 02, 2026 |
| CVE-2026-105049 | MEDIUM | 5.8 | Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public … | Oct 02, 2026 |
| CVE-2026-105048 | MEDIUM | 4.0 | The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses). | Oct 02, 2026 |
| CVE-2026-97363 | HIGH | 7.5 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service … | Oct 02, 2026 |
| CVE-2026-97212 | HIGH | 7.3 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results … | Oct 02, 2026 |
| CVE-2026-95102 | CRITICAL | 9.4 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to … | Oct 02, 2026 |
| CVE-2026-94594 | MEDIUM | 4.0 | Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this … | Oct 02, 2026 |
| CVE-2026-94593 | HIGH | 7.8 | Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the … | Oct 02, 2026 |
| CVE-2026-94592 | HIGH | 8.4 | Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per … | Oct 02, 2026 |
| CVE-2026-94591 | HIGH | 8.4 | Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and … | Oct 02, 2026 |
| CVE-2026-93474 | MEDIUM | 6.5 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. | Oct 02, 2026 |
| CVE-2026-105046 | MEDIUM | 4.3 | Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints. | Oct 02, 2026 |
| CVE-2026-105043 | LOW | 3.6 | MathWorks Simulink before R2026b, when showing a crafted .slx file, can have blocks that are never visible in the Simulink Editor but will cause code … | Oct 02, 2026 |
| CVE-2026-104887 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78409. Reason: This candidate is a duplicate of CVE-2026-78409. Notes: All CVE users … | Oct 02, 2026 |
| CVE-2026-104886 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-78410. Reason: This candidate is a duplicate of CVE-2026-78410. Notes: All CVE users … | Oct 02, 2026 |
| CVE-2026-82045 | MEDIUM | 6.5 | UTMStack before 11.2.16 contains a JPQL injection vulnerability that allows authenticated attackers to read arbitrary entity data by exploiting UtmNetworkScanService.searchPropertyValues(), which builds a JPQL query … | Oct 02, 2026 |
| CVE-2026-82044 | HIGH | 7.7 | UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated … | Oct 02, 2026 |
| CVE-2026-82043 | MEDIUM | 5.3 | UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST … | Oct 02, 2026 |
| CVE-2026-82042 | CRITICAL | 9.8 | UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching … | Oct 02, 2026 |
| CVE-2026-82041 | CRITICAL | 9.9 | UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist … | Oct 02, 2026 |
| CVE-2026-75937 | UNKNOWN | — | A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on … | Oct 02, 2026 |