Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-104480 | UNKNOWN | — | Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of … | Oct 02, 2026 |
| CVE-2026-104054 | MEDIUM | 6.3 | A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC … | Oct 02, 2026 |
| CVE-2026-104053 | MEDIUM | 6.3 | A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of … | Oct 02, 2026 |
| CVE-2026-104052 | MEDIUM | 6.3 | A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of … | Oct 02, 2026 |
| CVE-2026-103098 | HIGH | 7.5 | Transmission of a sensitive key in the URL over an unencrypted HTTP connection. The request is sent over HTTP rather than HTTPS, meaning the key … | Oct 02, 2026 |
| CVE-2026-103097 | HIGH | 7.5 | An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the … | Oct 02, 2026 |
| CVE-2026-103096 | HIGH | 7.5 | API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client … | Oct 02, 2026 |
| CVE-2026-86345 | CRITICAL | 9.0 | A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path … | Oct 02, 2026 |
| CVE-2026-103766 | HIGH | 7.2 | ClipBucket v5 through 5.5.3-#197 contains an sql injection vulnerability that allows authenticated users with ad_manager_access permission to inject SQL via the delete parameter in admin_area/ads_manager.php. … | Oct 02, 2026 |
| CVE-2026-103765 | CRITICAL | 9.4 | Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer … | Oct 02, 2026 |
| CVE-2026-103764 | CRITICAL | 9.8 | Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the … | Oct 02, 2026 |
| CVE-2026-103761 | HIGH | 7.5 | Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly … | Oct 01, 2026 |
| CVE-2026-103760 | MEDIUM | 5.9 | Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. … | Oct 01, 2026 |
| CVE-2025-71427 | MEDIUM | 6.8 | Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths … | Oct 01, 2026 |
| CVE-2026-86344 | HIGH | 7.5 | A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage … | Oct 01, 2026 |
| CVE-2026-71454 | UNKNOWN | — | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site Scripting (XSS). This issue affects CAPEC-63: … | Oct 01, 2026 |
| CVE-2026-71453 | UNKNOWN | — | - External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue affects EasyIO FS32: before 3.0b63. | Oct 01, 2026 |
| CVE-2026-71452 | UNKNOWN | — | - OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.0b63. | Oct 01, 2026 |
| CVE-2026-71449 | UNKNOWN | — | : Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63. | Oct 01, 2026 |
| CVE-2026-71448 | UNKNOWN | — | : Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affects EasyIO FS32: before 3.0b63. | Oct 01, 2026 |
| CVE-2026-64893 | UNKNOWN | — | - Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO: before … | Oct 01, 2026 |
| CVE-2026-64892 | UNKNOWN | — | - Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations. This issue affects Easy IO Neo: … | Oct 01, 2026 |
| CVE-2026-51897 | UNKNOWN | — | RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution | Oct 01, 2026 |
| CVE-2026-51896 | UNKNOWN | — | infiniflow ragflow 0.25.3 contains improper access control in resume (api/apps/connector_app.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing operations. | Oct 01, 2026 |
| CVE-2026-51895 | UNKNOWN | — | Ragflow 0.24.0 and prior contains improper access control in update_metadata_setting (api/apps/kb_app.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing operations. | Oct 01, 2026 |