Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54999
Total
4345
Critical
16386
High
16069
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-96655 | MEDIUM | 4.3 | Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses via the '/video/:/transcode/universal' path parameter. | Sep 23, 2026 |
| CVE-2026-96654 | MEDIUM | 6.5 | Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions and supply their … | Sep 23, 2026 |
| CVE-2026-96652 | MEDIUM | 4.3 | Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can include a full URL in the 'protocol' parameter and … | Sep 23, 2026 |
| CVE-2026-96651 | MEDIUM | 6.5 | Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path traversal via '/system/agents/media/get'. A … | Sep 23, 2026 |
| CVE-2026-96514 | HIGH | 7.3 | A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the file CafePortalLogin.php of the component Login Handler. This manipulation of … | Sep 23, 2026 |
| CVE-2026-96513 | HIGH | 7.3 | A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown processing of the file AddProductCode.php. The manipulation of the argument image … | Sep 23, 2026 |
| CVE-2026-95848 | UNKNOWN | — | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or authorizator class cannot be loaded, Server.initializeAuthenticator and Server.initializeAuthorizatorPolicy treat the … | Sep 23, 2026 |
| CVE-2026-95847 | UNKNOWN | — | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2PersistentQueue derives a session's message-map name as queue_ plus the client ID and its metadata-map … | Sep 23, 2026 |
| CVE-2026-95846 | UNKNOWN | — | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will message without applying the canWrite authorization and reserved-topic checks used … | Sep 23, 2026 |
| CVE-2026-95845 | UNKNOWN | — | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending per-session message queues. When a … | Sep 23, 2026 |
| CVE-2026-95844 | UNKNOWN | — | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette does not limit the depth of topic names and topic filters before processing them … | Sep 23, 2026 |
| CVE-2026-95843 | UNKNOWN | — | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.subscribe parses a shared-subscription filter through SharedSubscriptionUtils.extractShareName before validating the complete $share/{shareName}/{topicFilter} structure. A remote … | Sep 23, 2026 |
| CVE-2026-95842 | UNKNOWN | — | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEventLoop.run catches only InterruptedException, and SessionEventLoopGroup does not restart a terminated loop. An MQTT command … | Sep 23, 2026 |
| CVE-2026-93349 | HIGH | 8.8 | Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor … | Sep 23, 2026 |
| CVE-2026-88832 | HIGH | 7.3 | BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images. | Sep 23, 2026 |
| CVE-2026-88830 | HIGH | 7.5 | A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message. | Sep 23, 2026 |
| CVE-2026-85724 | CRITICAL | 9.6 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOperation substitutes client ID and username values directly into … | Sep 23, 2026 |
| CVE-2026-6669 | MEDIUM | 5.9 | Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in PgBouncer through 1.25.2 allows a malicious or … | Sep 23, 2026 |
| CVE-2026-6668 | HIGH | 7.5 | Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service. Sufficiently large … | Sep 23, 2026 |
| CVE-2026-19888 | HIGH | 7.5 | Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to crash the process. A … | Sep 23, 2026 |
| CVE-2025-63564 | CRITICAL | 9.8 | SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests | Sep 23, 2026 |
| CVE-2026-96675 | LOW | 3.3 | alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access. Attackers … | Sep 23, 2026 |
| CVE-2026-96674 | MEDIUM | 4.4 | alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted topology … | Sep 23, 2026 |
| CVE-2026-96673 | HIGH | 7.5 | Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated attackers to inject SQL by manipulating the album_id path … | Sep 23, 2026 |
| CVE-2026-96672 | MEDIUM | 6.4 | Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call(). Accounts Managers can … | Sep 23, 2026 |