Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54999
Total
4345
Critical
16386
High
16069
Medium
CVE ID Severity Score Description Published
CVE-2026-96655 MEDIUM 4.3 Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses via the '/video/:/transcode/universal' path parameter. Sep 23, 2026
CVE-2026-96654 MEDIUM 6.5 Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions and supply their … Sep 23, 2026
CVE-2026-96652 MEDIUM 4.3 Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can include a full URL in the 'protocol' parameter and … Sep 23, 2026
CVE-2026-96651 MEDIUM 6.5 Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path traversal via '/system/agents/media/get'. A … Sep 23, 2026
CVE-2026-96514 HIGH 7.3 A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the file CafePortalLogin.php of the component Login Handler. This manipulation of … Sep 23, 2026
CVE-2026-96513 HIGH 7.3 A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown processing of the file AddProductCode.php. The manipulation of the argument image … Sep 23, 2026
CVE-2026-95848 UNKNOWN — Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or authorizator class cannot be loaded, Server.initializeAuthenticator and Server.initializeAuthorizatorPolicy treat the … Sep 23, 2026
CVE-2026-95847 UNKNOWN — Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2PersistentQueue derives a session's message-map name as queue_ plus the client ID and its metadata-map … Sep 23, 2026
CVE-2026-95846 UNKNOWN — Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will message without applying the canWrite authorization and reserved-topic checks used … Sep 23, 2026
CVE-2026-95845 UNKNOWN — Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending per-session message queues. When a … Sep 23, 2026
CVE-2026-95844 UNKNOWN — Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette does not limit the depth of topic names and topic filters before processing them … Sep 23, 2026
CVE-2026-95843 UNKNOWN — Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.subscribe parses a shared-subscription filter through SharedSubscriptionUtils.extractShareName before validating the complete $share/{shareName}/{topicFilter} structure. A remote … Sep 23, 2026
CVE-2026-95842 UNKNOWN — Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEventLoop.run catches only InterruptedException, and SessionEventLoopGroup does not restart a terminated loop. An MQTT command … Sep 23, 2026
CVE-2026-93349 HIGH 8.8 Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor … Sep 23, 2026
CVE-2026-88832 HIGH 7.3 BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images. Sep 23, 2026
CVE-2026-88830 HIGH 7.5 A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message. Sep 23, 2026
CVE-2026-85724 CRITICAL 9.6 Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOperation substitutes client ID and username values directly into … Sep 23, 2026
CVE-2026-6669 MEDIUM 5.9 Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in PgBouncer through 1.25.2 allows a malicious or … Sep 23, 2026
CVE-2026-6668 HIGH 7.5 Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service. Sufficiently large … Sep 23, 2026
CVE-2026-19888 HIGH 7.5 Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to crash the process. A … Sep 23, 2026
CVE-2025-63564 CRITICAL 9.8 SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests Sep 23, 2026
CVE-2026-96675 LOW 3.3 alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access. Attackers … Sep 23, 2026
CVE-2026-96674 MEDIUM 4.4 alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted topology … Sep 23, 2026
CVE-2026-96673 HIGH 7.5 Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated attackers to inject SQL by manipulating the album_id path … Sep 23, 2026
CVE-2026-96672 MEDIUM 6.4 Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call(). Accounts Managers can … Sep 23, 2026