Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54243
Total
4300
Critical
16125
High
15819
Medium
CVE ID Severity Score Description Published
CVE-2026-104480 UNKNOWN — Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of … Oct 02, 2026
CVE-2026-104054 MEDIUM 6.3 A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC … Oct 02, 2026
CVE-2026-104053 MEDIUM 6.3 A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of … Oct 02, 2026
CVE-2026-104052 MEDIUM 6.3 A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of … Oct 02, 2026
CVE-2026-103098 HIGH 7.5 Transmission of a sensitive key in the URL over an unencrypted HTTP connection. The request is sent over HTTP rather than HTTPS, meaning the key … Oct 02, 2026
CVE-2026-103097 HIGH 7.5 An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the … Oct 02, 2026
CVE-2026-103096 HIGH 7.5 API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client … Oct 02, 2026
CVE-2026-86345 CRITICAL 9.0 A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path … Oct 02, 2026
CVE-2026-103766 HIGH 7.2 ClipBucket v5 through 5.5.3-#197 contains an sql injection vulnerability that allows authenticated users with ad_manager_access permission to inject SQL via the delete parameter in admin_area/ads_manager.php. … Oct 02, 2026
CVE-2026-103765 CRITICAL 9.4 Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer … Oct 02, 2026
CVE-2026-103764 CRITICAL 9.8 Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the … Oct 02, 2026
CVE-2026-103761 HIGH 7.5 Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly … Oct 01, 2026
CVE-2026-103760 MEDIUM 5.9 Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. … Oct 01, 2026
CVE-2025-71427 MEDIUM 6.8 Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths … Oct 01, 2026
CVE-2026-86344 HIGH 7.5 A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage … Oct 01, 2026
CVE-2026-71454 UNKNOWN — Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site Scripting (XSS). This issue affects CAPEC-63: … Oct 01, 2026
CVE-2026-71453 UNKNOWN — - External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue affects EasyIO FS32: before 3.0b63. Oct 01, 2026
CVE-2026-71452 UNKNOWN — - OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.0b63. Oct 01, 2026
CVE-2026-71449 UNKNOWN — : Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63. Oct 01, 2026
CVE-2026-71448 UNKNOWN — : Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affects EasyIO FS32: before 3.0b63. Oct 01, 2026
CVE-2026-64893 UNKNOWN — - Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO: before … Oct 01, 2026
CVE-2026-64892 UNKNOWN — - Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations. This issue affects Easy IO Neo: … Oct 01, 2026
CVE-2026-51897 UNKNOWN — RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution Oct 01, 2026
CVE-2026-51896 UNKNOWN — infiniflow ragflow 0.25.3 contains improper access control in resume (api/apps/connector_app.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing operations. Oct 01, 2026
CVE-2026-51895 UNKNOWN — Ragflow 0.24.0 and prior contains improper access control in update_metadata_setting (api/apps/kb_app.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing operations. Oct 01, 2026